Device42 records
6 published records for vendor device42.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-1400No exploit | Hardcoded encryption key IV in Exago WebReportsApi.dlldevice42 · cmdb · CWE-321 | Critical9.8 | — | 0.8% | Aug 16, 2022 |
36Monitor | CVE-2022-1401No exploit | Insufficient validation of provided paths in Exago WrImageResource.axddevice42 · cmdb · CWE-863 | High7.5 | — | 18.4% | Aug 16, 2022 |
36Monitor | CVE-2022-1399No exploit | Remote code execution in scheduled tasks componentdevice42 · cmdb · CWE-88 | Critical9.1 | — | 0.9% | Aug 16, 2022 |
35Monitor | CVE-2021-41315No exploit | The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility.device42 · remote collector · CWE-78 | High8.8 | — | 1.3% | Sep 17, 2021 |
35Monitor | CVE-2022-1410No exploit | Remote Code Execution in Device42 ApplianceManager consoledevice42 · cmdb · CWE-78 | High8.8 | — | 1.1% | Aug 16, 2022 |
32Monitor | CVE-2021-41316No exploit | The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility.device42 · device42 · CWE-88 | High8.1 | — | 1.4% | Sep 17, 2021 |
- CVE-2022-140039Monitor
Hardcoded encryption key IV in Exago WebReportsApi.dll
CriticalCVSS 9.8No exploitEPSS 1%device42 · cmdbAug 16, 2022
- CVE-2022-140136Monitor
Insufficient validation of provided paths in Exago WrImageResource.axd
HighCVSS 7.5No exploitEPSS 18%device42 · cmdbAug 16, 2022
- CVE-2022-139936Monitor
Remote code execution in scheduled tasks component
CriticalCVSS 9.1No exploitEPSS 1%device42 · cmdbAug 16, 2022
- CVE-2021-4131535Monitor
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility.
HighCVSS 8.8No exploitEPSS 1%device42 · remote collectorSep 17, 2021
- CVE-2022-141035Monitor
Remote Code Execution in Device42 ApplianceManager console
HighCVSS 8.8No exploitEPSS 1%device42 · cmdbAug 16, 2022
- CVE-2021-4131632Monitor
The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility.
HighCVSS 8.1No exploitEPSS 1%device42 · device42Sep 17, 2021