nch records
9 published records for vendor nch.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-426 Untrusted Search Path1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2021-37441No exploit | NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..nch · axon pbx · CWE-22 | High8.8 | — | 1.5% | Jul 25, 2021 |
33Monitor | CVE-2018-11552No exploit | There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.nch · axon pbx · CWE-79 | Medium6.1 | — | 28.6% | Jun 1, 2018 |
32Monitor | CVE-2018-11551No exploit | AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a tarnch · axon pbx · CWE-426 | High7.8 | — | 2.5% | Jun 1, 2018 |
26Monitor | CVE-2021-37469No exploit | In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..nch · webdictate · CWE-22 | Medium6.5 | — | 1.2% | Jul 25, 2021 |
26Monitor | CVE-2021-37440No exploit | NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..nch · axon pbx · CWE-22 | Medium6.5 | — | 1.2% | Jul 25, 2021 |
26Monitor | CVE-2021-37439No exploit | NCH FlexiServer v6.00 suffers from a syslog?file=/..nch · flexiserver · CWE-22 | Medium6.5 | — | 1.2% | Jul 25, 2021 |
22Monitor | CVE-2021-37452No exploit | NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configurnch · quorum · CWE-312 | Medium5.5 | — | 0.3% | Jul 25, 2021 |
18Monitor | CVE-2009-4038No exploit | Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrarnch · axon virtual pbx · CWE-79 | Medium4.3 | — | 2.4% | Nov 20, 2009 |
13Monitor | CVE-2021-37468No exploit | NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.nch · reflect customer relationship management · CWE-312 | Low3.3 | — | 0.2% | Jul 25, 2021 |
- CVE-2021-3744135Monitor
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..
HighCVSS 8.8No exploitEPSS 1%nch · axon pbxJul 25, 2021
- CVE-2018-1155233Monitor
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.
MediumCVSS 6.1No exploitEPSS 29%nch · axon pbxJun 1, 2018
- CVE-2018-1155132Monitor
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a tar
HighCVSS 7.8No exploitEPSS 2%nch · axon pbxJun 1, 2018
- CVE-2021-3746926Monitor
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..
MediumCVSS 6.5No exploitEPSS 1%nch · webdictateJul 25, 2021
- CVE-2021-3744026Monitor
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..
MediumCVSS 6.5No exploitEPSS 1%nch · axon pbxJul 25, 2021
- CVE-2021-3743926Monitor
NCH FlexiServer v6.00 suffers from a syslog?file=/..
MediumCVSS 6.5No exploitEPSS 1%nch · flexiserverJul 25, 2021
- CVE-2021-3745222Monitor
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configur
MediumCVSS 5.5No exploitEPSS 0%nch · quorumJul 25, 2021
- CVE-2009-403818Monitor
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrar
MediumCVSS 4.3No exploitEPSS 2%nch · axon virtual pbxNov 20, 2009
- CVE-2021-3746813Monitor
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
LowCVSS 3.3No exploitEPSS 0%nch · reflect customer relationship managementJul 25, 2021