Device42 kayıtları
device42 üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-1400İstismar yok | Hardcoded encryption key IV in Exago WebReportsApi.dlldevice42 · cmdb · CWE-321 | Kritik9,8 | — | %0,8 | 16 Ağu 2022 |
36İzleyin | CVE-2022-1401İstismar yok | Insufficient validation of provided paths in Exago WrImageResource.axddevice42 · cmdb · CWE-863 | Yüksek7,5 | — | %18,4 | 16 Ağu 2022 |
36İzleyin | CVE-2022-1399İstismar yok | Remote code execution in scheduled tasks componentdevice42 · cmdb · CWE-88 | Kritik9,1 | — | %0,9 | 16 Ağu 2022 |
35İzleyin | CVE-2021-41315İstismar yok | The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility.device42 · remote collector · CWE-78 | Yüksek8,8 | — | %1,3 | 17 Eyl 2021 |
35İzleyin | CVE-2022-1410İstismar yok | Remote Code Execution in Device42 ApplianceManager consoledevice42 · cmdb · CWE-78 | Yüksek8,8 | — | %1,1 | 16 Ağu 2022 |
32İzleyin | CVE-2021-41316İstismar yok | The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility.device42 · device42 · CWE-88 | Yüksek8,1 | — | %1,4 | 17 Eyl 2021 |
- CVE-2022-140039İzleyin
Hardcoded encryption key IV in Exago WebReportsApi.dll
KritikCVSS 9,8İstismar yokEPSS %1device42 · cmdb16 Ağu 2022
- CVE-2022-140136İzleyin
Insufficient validation of provided paths in Exago WrImageResource.axd
YüksekCVSS 7,5İstismar yokEPSS %18device42 · cmdb16 Ağu 2022
- CVE-2022-139936İzleyin
Remote code execution in scheduled tasks component
KritikCVSS 9,1İstismar yokEPSS %1device42 · cmdb16 Ağu 2022
- CVE-2021-4131535İzleyin
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility.
YüksekCVSS 8,8İstismar yokEPSS %1device42 · remote collector17 Eyl 2021
- CVE-2022-141035İzleyin
Remote Code Execution in Device42 ApplianceManager console
YüksekCVSS 8,8İstismar yokEPSS %1device42 · cmdb16 Ağu 2022
- CVE-2021-4131632İzleyin
The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility.
YüksekCVSS 8,1İstismar yokEPSS %1device42 · device4217 Eyl 2021