ericom records
3 published records for vendor ericom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 33.3%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2014-3913Weaponized | Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a requestericom · accessnow server · CWE-119 | Critical10.0 | — | 60.9% | Jun 4, 2014 |
24Monitor | CVE-2022-29152No exploit | The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.ericom · powerterm webconnect · CWE-79 | Medium6.1 | — | 0.6% | Apr 28, 2022 |
22Monitor | CVE-2020-24548No exploit | Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP portericom · access server · CWE-918 | Medium5.3 | — | 1.7% | Aug 26, 2020 |
- CVE-2014-391358Plan
Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request
CriticalCVSS 10.0WeaponizedEPSS 61%ericom · accessnow serverJun 4, 2014
- CVE-2022-2915224Monitor
The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.
MediumCVSS 6.1No exploitEPSS 1%ericom · powerterm webconnectApr 28, 2022
- CVE-2020-2454822Monitor
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP port
MediumCVSS 5.3No exploitEPSS 2%ericom · access serverAug 26, 2020