helpsystems records
7 published records for vendor helpsystems.
Researcher profile
- Entered KEV
- 2 · 28.6%
- Weaponized
- 2 · 28.6%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- 98 days
Recurring classes
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-281 Improper Preservation of Permissions1
- CWE-287 Improper Authentication1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
70This week | CVE-2022-42948Weaponized | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.helpsystems · cobalt strike · CWE-116 | Critical9.8 | KEV | 2.7% | Mar 24, 2023 |
68This week | CVE-2022-39197Weaponized | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTMhelpsystems · cobalt strike · CWE-79 | Medium6.1 | KEV | 46.4% | Sep 21, 2022 |
39Monitor | CVE-2018-20764No exploit | A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1.helpsystems · boks | Critical9.8 | — | 1.2% | Feb 8, 2019 |
31Monitor | CVE-2021-36798Proof of concept | A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3.helpsystems · cobalt strike · CWE-770 | High7.5 | — | 4.3% | Aug 9, 2021 |
30Monitor | CVE-2022-23317No exploit | CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant informatiohelpsystems · cobalt strike · CWE-287 | High7.5 | — | 1.1% | Feb 15, 2022 |
26Monitor | CVE-2021-46830No exploit | A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client.helpsystems · goanywhere managed file transfer · CWE-22 | Medium6.5 | — | 1.0% | Jul 27, 2022 |
22Monitor | CVE-2021-43708No exploit | The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel'helpsystems · titus data classification · CWE-281 | Medium5.5 | — | 0.3% | Apr 21, 2022 |
- CVE-2022-4294870This week
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.
CriticalCVSS 9.8KEVWeaponizedEPSS 3%helpsystems · cobalt strikeMar 24, 2023
- CVE-2022-3919768This week
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTM
MediumCVSS 6.1KEVWeaponizedEPSS 46%helpsystems · cobalt strikeSep 21, 2022
- CVE-2018-2076439Monitor
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1.
CriticalCVSS 9.8No exploitEPSS 1%helpsystems · boksFeb 8, 2019
- CVE-2021-3679831Monitor
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3.
HighCVSS 7.5Proof of conceptEPSS 4%helpsystems · cobalt strikeAug 9, 2021
- CVE-2022-2331730Monitor
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant informatio
HighCVSS 7.5No exploitEPSS 1%helpsystems · cobalt strikeFeb 15, 2022
- CVE-2021-4683026Monitor
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client.
MediumCVSS 6.5No exploitEPSS 1%helpsystems · goanywhere managed file transferJul 27, 2022
- CVE-2021-4370822Monitor
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel'
MediumCVSS 5.5No exploitEPSS 0%helpsystems · titus data classificationApr 21, 2022