CBOT records
6 published records for vendor cbot.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1270 Generation of Incorrect Security Tokens1
- CWE-1385 Missing Origin Validation in WebSockets1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-330 Use of Insufficiently Random Values1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-2887No exploit | User Authentication Bypass in CBOT's Chatbotcbot · cbot core · CWE-290 | Critical9.8 | — | 0.8% | May 25, 2023 |
39Monitor | CVE-2023-2884No exploit | Insecure Randomness in CBOT's Chatbotcbot · cbot core · CWE-330 | Critical9.8 | — | 0.7% | May 25, 2023 |
39Monitor | CVE-2023-2882No exploit | Privilege Escalation in CBOT's Chatbotcbot · cbot core · CWE-1270 | Critical9.8 | — | 0.6% | May 25, 2023 |
35Monitor | CVE-2023-2883No exploit | IDOR in CBOT's Chatbotcbot · cbot core · CWE-639 | High8.8 | — | 0.7% | May 25, 2023 |
32Monitor | CVE-2023-2885No exploit | Channel Accessible by Non-Endpoint in CBOT's Chatbotcbot · cbot core · CWE-924 | High8.1 | — | 0.3% | May 25, 2023 |
17Monitor | CVE-2023-2886No exploit | Cross-Site WebSocket Hijacking in CBOT's Chatbotcbot · cbot core · CWE-1385 | Medium4.3 | — | 0.2% | May 25, 2023 |
- CVE-2023-288739Monitor
User Authentication Bypass in CBOT's Chatbot
CriticalCVSS 9.8No exploitEPSS 1%cbot · cbot coreMay 25, 2023
- CVE-2023-288439Monitor
Insecure Randomness in CBOT's Chatbot
CriticalCVSS 9.8No exploitEPSS 1%cbot · cbot coreMay 25, 2023
- CVE-2023-288239Monitor
Privilege Escalation in CBOT's Chatbot
CriticalCVSS 9.8No exploitEPSS 1%cbot · cbot coreMay 25, 2023
- CVE-2023-288335Monitor
IDOR in CBOT's Chatbot
HighCVSS 8.8No exploitEPSS 1%cbot · cbot coreMay 25, 2023
- CVE-2023-288532Monitor
Channel Accessible by Non-Endpoint in CBOT's Chatbot
HighCVSS 8.1No exploitEPSS 0%cbot · cbot coreMay 25, 2023
- CVE-2023-288617Monitor
Cross-Site WebSocket Hijacking in CBOT's Chatbot
MediumCVSS 4.3No exploitEPSS 0%cbot · cbot coreMay 25, 2023