adremsoft records
8 published records for vendor adremsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-522 Insufficiently Protected Credentials1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-14482No exploit | AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-798 | Critical9.8 | — | 1.8% | Dec 16, 2020 |
39Monitor | CVE-2019-14480No exploit | AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication adremsoft · netcrunch · CWE-200 | Critical9.8 | — | 1.1% | Dec 16, 2020 |
36Monitor | CVE-2019-14479No exploit | AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution.adremsoft · netcrunch · CWE-78 | High8.8 | — | 4.2% | Dec 16, 2020 |
36Monitor | CVE-2019-14483No exploit | AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure.adremsoft · netcrunch | High8.8 | — | 1.8% | Dec 16, 2020 |
26Monitor | CVE-2019-14476No exploit | AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.adremsoft · netcrunch · CWE-918 | Medium6.5 | — | 0.8% | Dec 16, 2020 |
22Monitor | CVE-2019-14477No exploit | AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passworadremsoft · netcrunch · CWE-522 | Medium5.5 | — | 0.3% | Dec 16, 2020 |
21Monitor | CVE-2019-14478No exploit | AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-79 | Medium5.4 | — | 0.6% | Dec 16, 2020 |
21Monitor | CVE-2019-14481No exploit | AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-352 | Medium5.4 | — | 0.4% | Dec 16, 2020 |
- CVE-2019-1448240Plan
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client.
CriticalCVSS 9.8No exploitEPSS 2%adremsoft · netcrunchDec 16, 2020
- CVE-2019-1448039Monitor
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication
CriticalCVSS 9.8No exploitEPSS 1%adremsoft · netcrunchDec 16, 2020
- CVE-2019-1447936Monitor
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution.
HighCVSS 8.8No exploitEPSS 4%adremsoft · netcrunchDec 16, 2020
- CVE-2019-1448336Monitor
AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure.
HighCVSS 8.8No exploitEPSS 2%adremsoft · netcrunchDec 16, 2020
- CVE-2019-1447626Monitor
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.
MediumCVSS 6.5No exploitEPSS 1%adremsoft · netcrunchDec 16, 2020
- CVE-2019-1447722Monitor
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwor
MediumCVSS 5.5No exploitEPSS 0%adremsoft · netcrunchDec 16, 2020
- CVE-2019-1447821Monitor
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client.
MediumCVSS 5.4No exploitEPSS 1%adremsoft · netcrunchDec 16, 2020
- CVE-2019-1448121Monitor
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client.
MediumCVSS 5.4No exploitEPSS 0%adremsoft · netcrunchDec 16, 2020