{
  "schemaVersion": 1,
  "api": {
    "request": {
      "method": "GET",
      "url": "https://api.ismalicious.com/cve/CVE-2024-3400",
      "authentication": "Existing internal paid account; credentials omitted. This snapshot does not establish Free-tier access."
    },
    "capture": {
      "capturedAtUtc": "2026-10-09T07:19:11.951888Z",
      "status": 200,
      "rawResponseSha256": "1ab02feff7aea6961c8deaad45f525e59adfbd347ec5d115f6bdcf41dcee3c94"
    },
    "responseExcerpt": {
      "id": "CVE-2024-3400",
      "severity": "CRITICAL",
      "cvssScore": 10.0,
      "cvssVector": null,
      "published": "2024-04-12T08:15:06.230+00:00",
      "lastModified": "",
      "epssScore": 0.99999,
      "isKev": true,
      "kev": {
        "listed": true,
        "dateAdded": "2024-04-12T00:00:00+00:00",
        "dueDate": "2024-04-19T00:00:00+00:00"
      }
    },
    "productContext": {
      "label": "Palo Alto Networks PAN-OS / GlobalProtect",
      "sourceUrl": "https://nvd.nist.gov/vuln/detail/CVE-2024-3400",
      "scope": "Short product context, not a verified affected-package or installed-version match."
    },
    "epssVerification": {
      "url": "https://api.first.org/data/v1/epss?cve=CVE-2024-3400",
      "capturedAtUtc": "2026-10-09T07:20:34.590679Z",
      "rawResponseSha256": "7766f03e79e4d4bece4bda3f6c7237a4d8467a3f6db96965a9f2c5d6480dfaa8",
      "cve": "CVE-2024-3400",
      "epss": "0.999990000",
      "percentile": "1.000000000",
      "date": "2026-10-08",
      "dateOrigin": "FIRST public API, verified separately; the IsMalicious response does not include this score date."
    },
    "sources": [
      {
        "name": "NVD",
        "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3400"
      },
      {
        "name": "CISA KEV",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
      },
      {
        "name": "FIRST / Empirical Security",
        "url": "https://www.first.org/epss/"
      }
    ],
    "limitations": [
      "Selected fields from one response, not the full API payload or a coverage benchmark.",
      "EPSS is a model estimate for exploitation in the next 30 days, not certainty or IsMalicious detection accuracy. The percentile is separate from the probability.",
      "The KEV addition and due dates are historical dates, not the date of this API capture or a new remediation deadline.",
      "cvssVector is null and lastModified is empty in the captured response.",
      "An affected-package association was not corroborated and is excluded from the display. The product context does not verify a deployed version.",
      "No comparison with a customer tool, CERT feed, integration outcome or time saving is established."
    ]
  },
  "feedImport": {
    "collection": "malicious-ips",
    "capturedAtUtc": "2026-10-08T14:12:57.211277Z",
    "pagesCaptured": 2,
    "moreAfterLastPage": true,
    "tool": "OpenCTI",
    "version": "6.9.13",
    "clientVersion": "6.9.13",
    "inputEntries": 20,
    "uniqueStixObjects": 19,
    "importedIndicators": 18,
    "observablesCreated": 0,
    "rejectedIndicators": 0,
    "validUntilChanged": 18,
    "verifiedAtUtc": "2026-10-08T14:59:10.132607Z",
    "inputSha256": [
      "fd009dcd38ce044073ffca9a039c3ba0736c0da9d2652d36c6d3adb3f6cd1bf2",
      "22905de7f2c49da25286128a58b8585303edafbf29b05ad6a5cdad5134c172a2"
    ],
    "mappingValidationSha256": "6f9daadac4a77d3b18108a5d43c81c9d12f4a51529d2b3f04ef49eccdfca7d84",
    "scope": "Internal local sample import and GraphQL readback. This sample is separate from the CVE API example.",
    "limitations": [
      "No Observable was generated; no firewall export is established.",
      "valid_until changed for all imported Indicators; the cause is not established in this capture.",
      "Two pages only; more remained true. No complete collection pull or automated TAXII connector polling was tested.",
      "No customer production deployment, MISP or SIEM import, detection accuracy or commercial result is established."
    ]
  }
}
