Badge
11,371 badges added since 01 January 2025
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions

Coldwell Banker Realty is one of the nation’s largest real estate brokerages operating in 50 markets in the United States. Powered by a network of approximately 55,000 independent real estate agents and 600 offices, Coldwell Banker Realty, a subsidiary of Anywhere Real Estate Inc. (NYSE:HOUS), operates the company-owned real estate brokerage offices that are part of the worldwide Coldwell Banker Real Estate LLC brand. For more information, visit www.ColdwellBankerHomes.com.

Coldwell Banker Realty A.I CyberSecurity Scoring

CBR

Company Details

Linkedin ID:

cbrealty

Employees number:

44,752

Number of followers:

148,870

NAICS:

None

Industry Type:

Real Estate

Homepage:

coldwellbankerhomes.com

IP Addresses:

0

Company ID:

COL_1161607

Scan Status:

In-progress

AI scoreCBR Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/cbrealty.jpeg
CBR Real Estate
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
Get a Score Increase
globalscoreCBR Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/cbrealty.jpeg
CBR Real Estate
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

CBR Company CyberSecurity News & History

Past Incidents
2
Attack Types
2
EntityTypeSeverityImpactSeenBlog DetailsSupply Chain SourceIncident DetailsView
Anywhere Real Estate Inc.Breach8542/2026IvantiIvanti
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: Substack Discloses 2025 Data Breach Exposing User Email Addresses and Phone Numbers Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. In an email sent to affected account holders, CEO Chris Best confirmed that an unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure. The breach involved email addresses, phone numbers, and internal metadata, but Substack stated there is no evidence the data has been misused. The company has since patched the vulnerability and is conducting a full investigation while strengthening its security measures to prevent future incidents. No details were provided on the root cause of the breach or the total number of impacted users. Best apologized for the incident, acknowledging the company’s failure to adequately protect user data. Substack has not yet responded to requests for further clarification on the scope of the breach.

Anywhere Real Estate Inc.Ransomware10048/2025OracleOracle
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: Anywhere Real Estate Hit by Clop Ransomware Attack, Exposing 17,429 Customers In August, Anywhere Real Estate disclosed a data breach affecting 17,429 customers, following an attack by the Clop ransomware gang. The cybercriminals infiltrated the company’s Oracle E-Business Suite environment, accessing and potentially exfiltrating sensitive customer data. A breach notification filed with the Maine Attorney General’s Office confirmed the incident, though details on the exact nature of the compromised information remain limited. Clop, a well-known ransomware and extortion group, has been linked to multiple high-profile attacks, often targeting vulnerabilities in enterprise software. The breach at Anywhere Real Estate parent company of brands like Coldwell Banker, Century 21, and Sotheby’s International Realty highlights the growing threat to real estate and mortgage sectors, where vast amounts of personal and financial data are stored. The company has since notified impacted individuals, but the full scope of the breach’s consequences including potential identity theft or fraud remains unclear. This incident follows a broader trend of cyberattacks on real estate firms, underscoring the industry’s vulnerability to sophisticated ransomware operations.

Substack: Substack data breach exposed users’ emails and phone numbers
Breach
Severity: 85
Impact: 4
Seen: 2/2026
Blog:
Supply Chain Source: IvantiIvanti
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: Substack Discloses 2025 Data Breach Exposing User Email Addresses and Phone Numbers Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. In an email sent to affected account holders, CEO Chris Best confirmed that an unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure. The breach involved email addresses, phone numbers, and internal metadata, but Substack stated there is no evidence the data has been misused. The company has since patched the vulnerability and is conducting a full investigation while strengthening its security measures to prevent future incidents. No details were provided on the root cause of the breach or the total number of impacted users. Best apologized for the incident, acknowledging the company’s failure to adequately protect user data. Substack has not yet responded to requests for further clarification on the scope of the breach.

Anywhere Real Estate and Sotheby’s International Realty: Property records tech draws fresh VC interest; Anywhere data breach affects 17,000
Ransomware
Severity: 100
Impact: 4
Seen: 8/2025
Blog:
Supply Chain Source: OracleOracle
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: Anywhere Real Estate Hit by Clop Ransomware Attack, Exposing 17,429 Customers In August, Anywhere Real Estate disclosed a data breach affecting 17,429 customers, following an attack by the Clop ransomware gang. The cybercriminals infiltrated the company’s Oracle E-Business Suite environment, accessing and potentially exfiltrating sensitive customer data. A breach notification filed with the Maine Attorney General’s Office confirmed the incident, though details on the exact nature of the compromised information remain limited. Clop, a well-known ransomware and extortion group, has been linked to multiple high-profile attacks, often targeting vulnerabilities in enterprise software. The breach at Anywhere Real Estate parent company of brands like Coldwell Banker, Century 21, and Sotheby’s International Realty highlights the growing threat to real estate and mortgage sectors, where vast amounts of personal and financial data are stored. The company has since notified impacted individuals, but the full scope of the breach’s consequences including potential identity theft or fraud remains unclear. This incident follows a broader trend of cyberattacks on real estate firms, underscoring the industry’s vulnerability to sophisticated ransomware operations.

Ailogo

CBR Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for CBR

Incidents vs Real Estate Industry Average (This Year)

No incidents recorded for Coldwell Banker Realty in 2026.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Coldwell Banker Realty in 2026.

Incident Types CBR vs Real Estate Industry Avg (This Year)

No incidents recorded for Coldwell Banker Realty in 2026.

Incident History — CBR (X = Date, Y = Severity)

CBR cyber incidents detection timeline including parent company and subsidiaries

CBR Company Subsidiaries

SubsidiaryImage

Coldwell Banker Realty is one of the nation’s largest real estate brokerages operating in 50 markets in the United States. Powered by a network of approximately 55,000 independent real estate agents and 600 offices, Coldwell Banker Realty, a subsidiary of Anywhere Real Estate Inc. (NYSE:HOUS), operates the company-owned real estate brokerage offices that are part of the worldwide Coldwell Banker Real Estate LLC brand. For more information, visit www.ColdwellBankerHomes.com.

Loading...
similarCompanies

CBR Similar Companies

JLL

We’re a leading professional services firm that specializes in real estate and investment management. JLL shapes the future of real estate for a better world by using the most advanced technology to create rewarding opportunities, amazing spaces and sustainable real estate solutions for our clients,

CoStar Group

CoStar Group (NASDAQ: CSGP) is a global leader in commercial real estate information, analytics, online marketplaces, and 3D digital twin technology. Founded in 1986, CoStar Group is dedicated to digitizing the world’s real estate, empowering all people to discover properties, insights, and connecti

MEB Management Services (Morrison, Ekre & Bart Management Services)

MEB’S ability to create value for both clients and residents has been the cornerstone of our success. Scott, Libby, Mark, and Jodi have been active in the real estate management industry and have over 125 years of combined experience. With their breadth and depth of knowledge, MEB is the “go-to” co

REMAX

As one of the leading global real estate franchisors, RE/MAX, LLC is a subsidiary of RE/MAX Holdings (NYSE: RMAX) with more than 140,000 agents in almost 9,000 offices and a presence in more than 110 countries and territories. Nobody in the world sells more real estate than RE/MAX, as measured by

Colliers

We are a global diversified professional services and investment management company operating through three industry-leading businesses: Commercial Real Estate, Engineering, and Investment Management. With greater than a 30-year track record of consistent growth and strong recurring cash flows, we s

Shimao Group

Shimao Group has entered the real estate industry since 1989, After more than 30 years of development, the Group has made its layout in more than 100 core development cities across China, involving real estate, commercial, property management, hotel, theme entertainment and culture. Following the n

Coldwell Banker

Welcome to Coldwell Banker Real Estate LLC, a company founded in 1906 on a commitment to professionalism and customer service which remains the cornerstone of our business philosophy today. We are the nation’s oldest real estate company and our experience has helped make the dream of homeownership a

SM Supermalls

The SM Group of companies stands today as an institution, a store, a mall, a bank, a home, a resort, a hotel, and a place to see and experience with the family. One of the core business areas of the SM Group is the Shopping Center Management Corporation, generally referred to as SM Supermalls. The

Keller Williams Realty, LLC

Austin, Texas-based Keller Williams, the world’s largest real estate franchise by agent count, has more than 1,100 offices and 176,000 agents. The franchise is also No. 1 in units and sales volume in the United States. Since 1983, the company has cultivated an agent-centric, technology-driven, and

newsone

CBR CyberSecurity News

March 20, 2026 05:29 PM
Demand for homes is pretty healthy, says Coldwell Banker Realty CEO Kamini Lane

Kamini Lane, Coldwell Banker Realty CEO, joins 'The Exchange' to discuss the macro trends impacting homebuyers, recent all-cash deals and...

January 30, 2026 08:00 AM
How a Sarasota real estate team turned $161M in sales into No.1

Coldwell Banker Realty (COMP) announced that Pettingell Professionals — led by Roger Pettingell and Thomas Arbuckle — recorded more than...

January 30, 2026 08:00 AM
HOB Guys with Ties welcome cybersecurity pro

H.O. Brittingham Elementary School's Guys with Ties group welcomed ethical hacker Christopher Neuwirth Jan. 16 as a keynote speaker for an...

January 29, 2026 08:00 AM
Coldwell Banker Real Estate Announces 2025 Year-End Award Winners

Coldwell Banker Real Estate LLC today announced the 2025 recipients of its annual year-end awards, recognizing top‑ranking performers whose...

September 11, 2025 07:00 AM
Cybersecurity risks rise with smart home devices

COLUMBUS, Ohio — As more Ohio families add smart technology such as video doorbells and Wi-Fi thermostats to their homes, cybersecurity...

June 17, 2025 07:00 AM
Coldwell Banker Real Estate Unveils 2025 List of "30 Under 30" Honorees

This annual recognition celebrates the achievements of Coldwell Banker-affiliated real estate professionals under the age of 30 who have demonstrated...

January 23, 2025 08:00 AM
Coldwell Banker Announces 2024 Year-End Award Winners

Coldwell Banker Real Estate LLC, an Anywhere® (NYSE: HOUS) brand, today announced the recipients of its prestigious 2024 year-end awards.

May 30, 2024 07:00 AM
Local officials attend workshop on cybersecurity, water contaminants

Nearly 20 local town managers, public works administrators and water plant operators participated in Need to Know: Water Essentials, a workshop held May 3.

December 15, 2023 08:00 AM
The Ten: Cyberattacks exposed real estate's vulnerabilities — and strengths

In a year when the real estate industry felt under attack from all sides, hackers decided to pile on, disrupting closings, listings and mortgages.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

CBR CyberSecurity History Information

Official Website of Coldwell Banker Realty

The official website of Coldwell Banker Realty is http://www.coldwellbankerhomes.com.

Coldwell Banker Realty’s AI-Generated Cybersecurity Score

According to Rankiteo, Coldwell Banker Realty’s AI-generated cybersecurity score is 788, reflecting their Fair security posture.

How many security badges does Coldwell Banker Realty’ have ?

According to Rankiteo, Coldwell Banker Realty currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Has Coldwell Banker Realty been affected by any supply chain cyber incidents ?

According to Rankiteo, Coldwell Banker Realty has been affected by multiple supply chain cyber incidents. The affected supply chain sources and their corresponding incident IDs are:

  • Ivanti (Incident ID: SUB1770295740)
  • Oracle (Incident ID: ANYSOT1770810849)
Does Coldwell Banker Realty have SOC 2 Type 1 certification ?

According to Rankiteo, Coldwell Banker Realty is not certified under SOC 2 Type 1.

Does Coldwell Banker Realty have SOC 2 Type 2 certification ?

According to Rankiteo, Coldwell Banker Realty does not hold a SOC 2 Type 2 certification.

Does Coldwell Banker Realty comply with GDPR ?

According to Rankiteo, Coldwell Banker Realty is not listed as GDPR compliant.

Does Coldwell Banker Realty have PCI DSS certification ?

According to Rankiteo, Coldwell Banker Realty does not currently maintain PCI DSS compliance.

Does Coldwell Banker Realty comply with HIPAA ?

According to Rankiteo, Coldwell Banker Realty is not compliant with HIPAA regulations.

Does Coldwell Banker Realty have ISO 27001 certification ?

According to Rankiteo,Coldwell Banker Realty is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Coldwell Banker Realty

Coldwell Banker Realty operates primarily in the Real Estate industry.

Number of Employees at Coldwell Banker Realty

Coldwell Banker Realty employs approximately 44,752 people worldwide.

Subsidiaries Owned by Coldwell Banker Realty

Coldwell Banker Realty presently has no subsidiaries across any sectors.

Coldwell Banker Realty’s LinkedIn Followers

Coldwell Banker Realty’s official LinkedIn profile has approximately 148,870 followers.

NAICS Classification of Coldwell Banker Realty

Coldwell Banker Realty is classified under the NAICS code None, which corresponds to Others.

Coldwell Banker Realty’s Presence on Crunchbase

No, Coldwell Banker Realty does not have a profile on Crunchbase.

Coldwell Banker Realty’s Presence on LinkedIn

Yes, Coldwell Banker Realty maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/cbrealty.

Cybersecurity Incidents Involving Coldwell Banker Realty

As of April 02, 2026, Rankiteo reports that Coldwell Banker Realty has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Coldwell Banker Realty has an estimated 29,970 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Coldwell Banker Realty ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach and Ransomware.

How does Coldwell Banker Realty detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with patched the vulnerability, and remediation measures with strengthening security measures, and communication strategy with email notification to affected users, and communication strategy with notified impacted individuals via breach notification..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Substack 2025 Data Breach Exposing User Email Addresses and Phone Numbers

Description: Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. An unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure. The breach involved email addresses, phone numbers, and internal metadata, but there is no evidence the data has been misused.

Date Detected: 2025-02-03

Type: Data Breach

Threat Actor: Unauthorized third party

Incident : Ransomware

Title: Anywhere Real Estate Hit by Clop Ransomware Attack, Exposing 17,429 Customers

Description: In August, Anywhere Real Estate disclosed a data breach affecting 17,429 customers, following an attack by the Clop ransomware gang. The cybercriminals infiltrated the company’s Oracle E-Business Suite environment, accessing and potentially exfiltrating sensitive customer data. A breach notification filed with the Maine Attorney General’s Office confirmed the incident, though details on the exact nature of the compromised information remain limited.

Date Publicly Disclosed: 2023-08

Type: Ransomware

Attack Vector: Vulnerability in enterprise software

Vulnerability Exploited: Oracle E-Business Suite

Threat Actor: Clop ransomware gang

Motivation: Extortion

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach SUB1770295740

Data Compromised: Email addresses, phone numbers, internal metadata

Brand Reputation Impact: Acknowledged failure to protect user data

Payment Information Risk: None (credit card details and financial information remained secure)

Incident : Ransomware ANYSOT1770810849

Data Compromised: Sensitive customer data

Systems Affected: Oracle E-Business Suite

Identity Theft Risk: Potential

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Email addresses, phone numbers, internal metadata and Sensitive customer data.

Which entities were affected by each incident ?

Incident : Data Breach SUB1770295740

Entity Name: Substack

Entity Type: Company

Industry: Publishing/Technology

Incident : Ransomware ANYSOT1770810849

Entity Name: Anywhere Real Estate

Entity Type: Corporation

Industry: Real Estate

Customers Affected: 17,429

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach SUB1770295740

Containment Measures: Patched the vulnerability

Remediation Measures: Strengthening security measures

Communication Strategy: Email notification to affected users

Incident : Ransomware ANYSOT1770810849

Communication Strategy: Notified impacted individuals via breach notification

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach SUB1770295740

Type of Data Compromised: Email addresses, phone numbers, internal metadata

Sensitivity of Data: Moderate (PII but no financial data)

Personally Identifiable Information: Email addresses, phone numbers

Incident : Ransomware ANYSOT1770810849

Type of Data Compromised: Sensitive customer data

Number of Records Exposed: 17,429

Sensitivity of Data: High

Data Exfiltration: Potential

Personally Identifiable Information: Potential

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Strengthening security measures.

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by patched the vulnerability.

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : Ransomware ANYSOT1770810849

Ransomware Strain: Clop

Data Exfiltration: Potential

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Ransomware ANYSOT1770810849

Regulatory Notifications: Maine Attorney General’s Office

References

Where can I find more information about each incident ?

Incident : Data Breach SUB1770295740

Source: Substack Notification Email

Incident : Ransomware ANYSOT1770810849

Source: Maine Attorney General’s Office

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Substack Notification Email, and Source: Maine Attorney General’s Office.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Breach SUB1770295740

Investigation Status: Ongoing

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Email notification to affected users and Notified impacted individuals via breach notification.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Data Breach SUB1770295740

Customer Advisories: Email notification sent to affected users

Incident : Ransomware ANYSOT1770810849

Customer Advisories: Notified impacted individuals

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Email notification sent to affected users and Notified impacted individuals.

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach SUB1770295740

Corrective Actions: Strengthening security measures

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Strengthening security measures.

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident were an Unauthorized third party and Clop ransomware gang.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2025-02-03.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-08.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Email addresses, phone numbers, internal metadata and Sensitive customer data.

Response to the Incidents

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Patched the vulnerability.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Email addresses, phone numbers, internal metadata and Sensitive customer data.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 17.4K.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Maine Attorney General’s Office and Substack Notification Email.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.

Stakeholder and Customer Advisories

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued were an Email notification sent to affected users and Notified impacted individuals.

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=cbrealty' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge