Reading the observatory store…
Reading the observatory store…
First seen 22 Sep 2026, last seen 23 Sep 2026 22:40 UTC (16h ago). 2 observations on record. Location is an estimate derived from registration data — the source and confidence are stated below.
| Port | Service | Product | Technologies | TLS | State | Banner | Last seen |
|---|---|---|---|---|---|---|---|
| 22 tcp / tcp | ssh | OpenSSH 7.4 |
| not negotiated | open | SSH-2.0-OpenSSH_7.4 | 23 Sep 2026 16h ago |
| 80 tcp / tcp | http | Apache HTTP Server 2.4.6 |
| not negotiated | open | no banner captured | 23 Sep 2026 16h ago |
| Observed at | Source | Collector | Confidence | Changed | State | Content hash |
|---|---|---|---|---|---|---|
| 23 Sep 2026 22:40 UTC | fingerprint | fingerprint-1 | high | changed | {"services":{"22/tcp":{"state":"open","product":"OpenSSH","version":"7.4","cert_sha256":"","tls_version":"","service_type":"ssh"},"80/tcp":{"state":"open","pro… | c9c5e45959144a759489623ae6f022b44c28e9a… |
| 22 Sep 2026 09:30 UTC | fingerprint | fingerprint-1 | high | changed | {} | 18a8832abfaec9e7e15cfd91e540b992d7c88f8… |
| Detected at | Type | Field | Previous | Current | Significance | Confidence |
|---|---|---|---|---|---|---|
| 23 Sep 2026 22:40 UTC | TECHNOLOGY CHANGED | — | — | apache-http-server, openssh | low | unknown |
| 23 Sep 2026 22:40 UTC | NEW SERVICE | service:80/tcp | — | Apache HTTP Server 2.4.6 | low | unknown |
| 23 Sep 2026 22:40 UTC | NEW SERVICE | service:22/tcp | — | OpenSSH 7.4 | low | unknown |
| 22 Sep 2026 09:30 UTC | NEW ASSET | — | — | asset with no observed open endpoints | low | unknown |
6 matches on this asset, each one unverified. Treat these as leads for manual review, never as findings.
| Identifier | Severity | CVSS | Product / version | Status | Match confidence | Evidence | Detected |
|---|---|---|---|---|---|---|---|
CVE-2023-35812 An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered c… | medium | 5.3 | OpenSSH 7.4 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"OpenSSH 7.4\"","note":"version-string match only; not a confirmed exposure","observ… | 23 Sep 2026 |
CVE-2016-10708 sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, relat… | high | 7.5 | OpenSSH 7.4 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"OpenSSH 7.4\"","note":"version-string match only; not a confirmed exposure","observ… | 23 Sep 2026 |
CVE-2016-10012 The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local use… | high | 7.8 | OpenSSH 7.4 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"OpenSSH 7.4\"","note":"version-string match only; not a confirmed exposure","observ… | 23 Sep 2026 |
CVE-2016-10011 authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging … | medium | 6.2 | OpenSSH 7.4 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"OpenSSH 7.4\"","note":"version-string match only; not a confirmed exposure","observ… | 23 Sep 2026 |
CVE-2016-10010 sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to … | high | 7.0 | OpenSSH 7.4 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"OpenSSH 7.4\"","note":"version-string match only; not a confirmed exposure","observ… | 23 Sep 2026 |
CVE-2016-10009 Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-s… | high | 7.3 | OpenSSH 7.4 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"OpenSSH 7.4\"","note":"version-string match only; not a confirmed exposure","observ… | 23 Sep 2026 |
| Field | Previous | Current | Reading |
|---|---|---|---|
| services.22/tcp.cert_sha256 | — | — | appeared |
| services.22/tcp.product | — | OpenSSH | appeared |
| services.22/tcp.service_type | — | ssh | appeared |
| services.22/tcp.state | — | open | appeared |
| services.22/tcp.tls_version | — | — | appeared |
| services.22/tcp.version | — | 7.4 | appeared |
| services.80/tcp.cert_sha256 | — | — | appeared |
| services.80/tcp.product | — | Apache HTTP Server | appeared |
| services.80/tcp.service_type | — | http | appeared |
| services.80/tcp.state | — | open | appeared |
| services.80/tcp.tls_version | — | — | appeared |
| services.80/tcp.version | — | 2.4.6 | appeared |
| technologies | — | ["apache-http-server","openssh"] | appeared |
{
"id": "cbf636307cce913eaee0e56021b7f1761",
"type": "ipv4",
"value": "160.22.164.201",
"hostname": null,
"reverseDns": null,
"asn": {
"number": 138933,
"name": "FNCPL-AS-AP - Fiber Net Communication Pvt. Ltd."
},
"organization": {
"id": "cc62da4db4cb7519b9d19b6ffb57e799d",
"name": "FNCPL-AS-AP - Fiber Net Communication Pvt. Ltd."
},
"location": {
"country": "NP",
"city": "Kathmandu",
"province": "Bagmati Province",
"district": "",
"confidence": "low",
"source": "ip-api.com"
},
"scopeStatus": "in_scope",
"priority": "NORMAL",
"firstSeen": "2026-09-22T05:02:16.804Z",
"lastSeen": "2026-09-23T22:40:17.850Z",
"observationCount": 2,
"openServices": 2,
"serviceCount": 2,
"technologies": [
"apache-http-server",
"openssh"
],
"vulnerabilityMatches": [
{
"id": "ca2eaca4bdfd8cb9c52e74829f2cbf2dd",
"cve": "CVE-2023-35812",
"severity": "medium",
"cvssScore": 5.3,
"summary": "An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered cases where an absolute path is passed to scp. When a relative path is used, there is no verification that the name of a file received by the client matches the file requested. Fixed packages are available with numbers 7.4p1-22.78.amzn1 and 7.4p1-22.amzn2.0.2.",
"product": "OpenSSH",
"version": "7.4",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"OpenSSH 7.4\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"OpenSSH\",\"observed_version\":\"7.4\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-23T23:55:18.185Z",
"assetValue": "160.22.164.201",
"serviceId": "cec22d50da02e6cb3f1bbe6d659dff6f4",
"port": 22,
"technologySlug": "openssh"
},
{
"id": "c48bf7a866f55fec1a422d36fa570e6a8",
"cve": "CVE-2016-10708",
"severity": "high",
"cvssScore": 7.5,
"summary": "sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.",
"product": "OpenSSH",
"version": "7.4",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"OpenSSH 7.4\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"OpenSSH\",\"observed_version\":\"7.4\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-23T23:55:18.183Z",
"assetValue": "160.22.164.201",
"serviceId": "cec22d50da02e6cb3f1bbe6d659dff6f4",
"port": 22,
"technologySlug": "openssh"
},
{
"id": "c1de35315ad99ddd88f3339b5fdd4d2e1",
"cve": "CVE-2016-10012",
"severity": "high",
"cvssScore": 7.8,
"summary": "The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.",
"product": "OpenSSH",
"version": "7.4",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"OpenSSH 7.4\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"OpenSSH\",\"observed_version\":\"7.4\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-23T23:55:18.180Z",
"assetValue": "160.22.164.201",
"serviceId": "cec22d50da02e6cb3f1bbe6d659dff6f4",
"port": 22,
"technologySlug": "openssh"
},
{
"id": "cde9f6e46458a3be09a9877cb10647b2c",
"cve": "CVE-2016-10011",
"severity": "medium",
"cvssScore": 6.2,
"summary": "authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.",
"product": "OpenSSH",
"version": "7.4",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"OpenSSH 7.4\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"OpenSSH\",\"observed_version\":\"7.4\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-23T23:55:18.177Z",
"assetValue": "160.22.164.201",
"serviceId": "cec22d50da02e6cb3f1bbe6d659dff6f4",
"port": 22,
"technologySlug": "openssh"
},
{
"id": "c9b03cfe6d139fe071fc902b4cd8a2ef5",
"cve": "CVE-2016-10010",
"severity": "high",
"cvssScore": 7,
"summary": "sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.",
"product": "OpenSSH",
"version": "7.4",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"OpenSSH 7.4\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"OpenSSH\",\"observed_version\":\"7.4\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-23T23:55:18.173Z",
"assetValue": "160.22.164.201",
"serviceId": "cec22d50da02e6cb3f1bbe6d659dff6f4",
"port": 22,
"technologySlug": "openssh"
},
{
"id": "c7167364e83fd02b9f28392da93b294f5",
"cve": "CVE-2016-10009",
"severity": "high",
"cvssScore": 7.3,
"summary": "Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.",
"product": "OpenSSH",
"version": "7.4",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"OpenSSH 7.4\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"OpenSSH\",\"observed_version\":\"7.4\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-23T23:55:18.170Z",
"assetValue": "160.22.164.201",
"serviceId": "cec22d50da02e6cb3f1bbe6d659dff6f4",
"port": 22,
"technologySlug": "openssh"
}
],
"network": {
"id": "ca43a96b40a20340a942034d229700802",
"prefix": "160.22.164.0/24",
"ipVersion": 4
},
"services": [
{
"id": "cec22d50da02e6cb3f1bbe6d659dff6f4",
"assetId": "cbf636307cce913eaee0e56021b7f1761",
"assetValue": null,
"port": 22,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "ssh",
"product": "OpenSSH",
"productVersion": "7.4",
"tlsVersion": null,
"banner": "SSH-2.0-OpenSSH_7.4",
"state": "open",
"firstSeen": "2026-09-23T22:40:17.825Z",
"lastSeen": "2026-09-23T22:40:17.825Z",
"observationCount": 0,
"technologies": [
{
"slug": "openssh",
"name": "OpenSSH",
"category": "remote-access",
"vendor": "OpenBSD Project",
"version": "7.4",
"confidence": "high",
"evidence": "SSH banner: SSH-2.0-OpenSSH_7.4",
"detectedAt": "2026-09-23T22:40:17.828Z"
}
],
"certificate": null
},
{
"id": "cfdce110bee4aa437e875b08304263aaa",
"assetId": "cbf636307cce913eaee0e56021b7f1761",
"assetValue": null,
"port": 80,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "http",
"product": "Apache HTTP Server",
"productVersion": "2.4.6",
"tlsVersion": null,
"banner": null,
"state": "open",
"firstSeen": "2026-09-23T22:40:17.833Z",
"lastSeen": "2026-09-23T22:40:17.833Z",
"observationCount": 0,
"technologies": [
{
"slug": "apache-http-server",
"name": "Apache HTTP Server",
"category": "web-server",
"vendor": "Apache Software Foundation",
"version": "2.4.6",
"confidence": "high",
"evidence": "server: Apache/2.4.6 (CentOS) mod_fcgid/2.3.9",
"detectedAt": "2026-09-23T22:40:17.836Z"
}
],
"certificate": null
}
],
"certificates": [],
"recentObservations": [
{
"id": "c269c84613c0f7d50c147d08265764750",
"observedAt": "2026-09-23T22:40:17.841Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {
"services": {
"22/tcp": {
"state": "open",
"product": "OpenSSH",
"version": "7.4",
"cert_sha256": "",
"tls_version": "",
"service_type": "ssh"
},
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.6",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
}
},
"technologies": [
"apache-http-server",
"openssh"
]
},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
465,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 2,
"reachable": true,
"reverse_dns": "",
"ports_probed": 26,
"technologies": [
"apache-http-server",
"openssh"
],
"open_services": 2,
"probe_duration": 25093
},
"contentHash": "c9c5e45959144a759489623ae6f022b44c28e9ac7181758a81d2b11b7b690ab1",
"changed": true
},
{
"id": "c30d584b1405055a6fe2568f4aec226f9",
"observedAt": "2026-09-22T09:30:12.665Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 0,
"reachable": false,
"reverse_dns": "",
"ports_probed": 25,
"technologies": null,
"open_services": 0,
"probe_duration": 42
},
"contentHash": "18a8832abfaec9e7e15cfd91e540b992d7c88f8ef9006b5112f00a99ce56cae0",
"changed": true
}
],
"recentChanges": [
{
"id": "cc468d5743a36135fedc741920c4b4c99",
"changeType": "TECHNOLOGY_CHANGED",
"assetId": "cbf636307cce913eaee0e56021b7f1761",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "apache-http-server, openssh",
"detectedAt": "2026-09-23T22:40:17.848Z",
"significance": "low",
"severity": "info",
"confidence": null,
"detail": "technology detected: apache-http-server, openssh",
"serviceId": null
},
{
"id": "cf825e137217db000ca0f40952a15cf1a",
"changeType": "NEW_SERVICE",
"assetId": "cbf636307cce913eaee0e56021b7f1761",
"assetValue": null,
"field": "service:80/tcp",
"previousValue": null,
"currentValue": "Apache HTTP Server 2.4.6",
"detectedAt": "2026-09-23T22:40:17.846Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "newly observed open endpoint",
"serviceId": null
},
{
"id": "cd3c3c0a6047d89cdbf0aa8e9b2a30518",
"changeType": "NEW_SERVICE",
"assetId": "cbf636307cce913eaee0e56021b7f1761",
"assetValue": null,
"field": "service:22/tcp",
"previousValue": null,
"currentValue": "OpenSSH 7.4",
"detectedAt": "2026-09-23T22:40:17.844Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "newly observed open endpoint",
"serviceId": null
},
{
"id": "cf3dbd4b7acc6331ab024d672062bb64d",
"changeType": "NEW_ASSET",
"assetId": "cbf636307cce913eaee0e56021b7f1761",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "asset with no observed open endpoints",
"detectedAt": "2026-09-22T09:30:12.666Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "asset observed for the first time",
"serviceId": null
}
],
"dnsRecords": [],
"state": {
"current": {
"services": {
"22/tcp": {
"state": "open",
"product": "OpenSSH",
"version": "7.4",
"cert_sha256": "",
"tls_version": "",
"service_type": "ssh"
},
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.6",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
}
},
"technologies": [
"apache-http-server",
"openssh"
]
},
"previous": {},
"comparable": true
}
}