code42 records
10 published records for vendor code42.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-426 Untrusted Search Path2
- CWE-269 Improper Privilege Management2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-502 Deserialization of Untrusted Data1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2017-9830Proof of concept | Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiaticode42 · crashplan · CWE-502 | Critical9.8 | — | 6.5% | Jun 27, 2017 |
40Plan | CVE-2019-15131No exploit | In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files tocode42 · code42 · CWE-434 | Critical9.8 | — | 1.9% | Sep 17, 2019 |
35Monitor | CVE-2021-43269No exploit | In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config code42 · code42 · CWE-94 | High8.8 | — | 1.3% | Jan 19, 2022 |
35Monitor | CVE-2019-11553No exploit | In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organizatcode42 · code42 · CWE-269 | High8.8 | — | 1.0% | Jul 19, 2019 |
31Monitor | CVE-2018-20131No exploit | The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashpcode42 · code42 · CWE-732 | High7.8 | — | 0.3% | Jan 2, 2019 |
29Monitor | CVE-2020-12736No exploit | Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution.code42 · code42 · CWE-74 | High7.2 | — | 2.0% | Jul 7, 2020 |
29Monitor | CVE-2019-16861No exploit | Code42 server through 7.0.2 for Windows has an Untrusted Search Path.code42 · code42 · CWE-426 | High7.3 | — | 0.4% | Nov 19, 2019 |
29Monitor | CVE-2019-16860No exploit | Code42 app through version 7.0.2 for Windows has an Untrusted Search Path.code42 · code42 · CWE-426 | High7.3 | — | 0.4% | Nov 19, 2019 |
28Monitor | CVE-2019-11552No exploit | Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injeccode42 · code42 for enterprise · CWE-94 | High7.0 | — | 0.5% | Jul 19, 2019 |
22Monitor | CVE-2019-11551No exploit | In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a filcode42 · code42 for enterprise · CWE-269 | Medium5.5 | — | 0.3% | Aug 21, 2019 |
- CVE-2017-983041Plan
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiati
CriticalCVSS 9.8Proof of conceptEPSS 6%code42 · crashplanJun 27, 2017
- CVE-2019-1513140Plan
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to
CriticalCVSS 9.8No exploitEPSS 2%code42 · code42Sep 17, 2019
- CVE-2021-4326935Monitor
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config
HighCVSS 8.8No exploitEPSS 1%code42 · code42Jan 19, 2022
- CVE-2019-1155335Monitor
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organizat
HighCVSS 8.8No exploitEPSS 1%code42 · code42Jul 19, 2019
- CVE-2018-2013131Monitor
The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashp
HighCVSS 7.8No exploitEPSS 0%code42 · code42Jan 2, 2019
- CVE-2020-1273629Monitor
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution.
HighCVSS 7.2No exploitEPSS 2%code42 · code42Jul 7, 2020
- CVE-2019-1686129Monitor
Code42 server through 7.0.2 for Windows has an Untrusted Search Path.
HighCVSS 7.3No exploitEPSS 0%code42 · code42Nov 19, 2019
- CVE-2019-1686029Monitor
Code42 app through version 7.0.2 for Windows has an Untrusted Search Path.
HighCVSS 7.3No exploitEPSS 0%code42 · code42Nov 19, 2019
- CVE-2019-1155228Monitor
Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injec
HighCVSS 7.0No exploitEPSS 1%code42 · code42 for enterpriseJul 19, 2019
- CVE-2019-1155122Monitor
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a fil
MediumCVSS 5.5No exploitEPSS 0%code42 · code42 for enterpriseAug 21, 2019