Skip to content
Noroxi

code42 records

10 published records for vendor code42.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

10 records
  • Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiati

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    code42 · crashplanJun 27, 2017

  • In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to

    CriticalCVSS 9.8No exploitEPSS 2%

    code42 · code42Sep 17, 2019

  • In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config

    HighCVSS 8.8No exploitEPSS 1%

    code42 · code42Jan 19, 2022

  • In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organizat

    HighCVSS 8.8No exploitEPSS 1%

    code42 · code42Jul 19, 2019

  • The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashp

    HighCVSS 7.8No exploitEPSS 0%

    code42 · code42Jan 2, 2019

  • Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution.

    HighCVSS 7.2No exploitEPSS 2%

    code42 · code42Jul 7, 2020

  • Code42 server through 7.0.2 for Windows has an Untrusted Search Path.

    HighCVSS 7.3No exploitEPSS 0%

    code42 · code42Nov 19, 2019

  • Code42 app through version 7.0.2 for Windows has an Untrusted Search Path.

    HighCVSS 7.3No exploitEPSS 0%

    code42 · code42Nov 19, 2019

  • Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injec

    HighCVSS 7.0No exploitEPSS 1%

    code42 · code42 for enterpriseJul 19, 2019

  • In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a fil

    MediumCVSS 5.5No exploitEPSS 0%

    code42 · code42 for enterpriseAug 21, 2019