kramerav records
8 published records for vendor kramerav.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-269 Improper Privilege Management1
- CWE-276 Incorrect Default Permissions1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2021-35064Proof of concept | KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo.kramerav · viaware · CWE-269 | Critical9.8 | — | 70.8% | Jul 12, 2021 |
55Plan | CVE-2021-36356Proof of concept | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts akramerav · viaware · CWE-434 | Critical9.8 | — | 54.4% | Aug 31, 2021 |
46Plan | CVE-2019-17124Proof of concept | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.kramerav · viaware · CWE-276 | Critical9.8 | — | 22.5% | Oct 9, 2019 |
39Monitor | CVE-2023-33508No exploit | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).kramerav · via go2 firmware · CWE-434 | Critical9.8 | — | 1.4% | May 31, 2023 |
39Monitor | CVE-2023-33509No exploit | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.kramerav · via go2 firmware · CWE-89 | Critical9.8 | — | 0.8% | May 31, 2023 |
36Monitor | CVE-2023-33468No exploit | KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation kramerav · via go2 firmware · CWE-863 | Critical9.1 | — | 0.8% | Aug 9, 2023 |
31Monitor | CVE-2023-33469No exploit | In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a verskramerav · via go2 firmware · CWE-94 | High7.8 | — | 0.3% | Aug 9, 2023 |
30Monitor | CVE-2023-33507No exploit | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.kramerav · via go2 firmware | High7.5 | — | 0.7% | May 31, 2023 |
- CVE-2021-3506460This week
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo.
CriticalCVSS 9.8Proof of conceptEPSS 71%kramerav · viawareJul 12, 2021
- CVE-2021-3635655Plan
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts a
CriticalCVSS 9.8Proof of conceptEPSS 54%kramerav · viawareAug 31, 2021
- CVE-2019-1712446Plan
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
CriticalCVSS 9.8Proof of conceptEPSS 23%kramerav · viawareOct 9, 2019
- CVE-2023-3350839Monitor
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
CriticalCVSS 9.8No exploitEPSS 1%kramerav · via go2 firmwareMay 31, 2023
- CVE-2023-3350939Monitor
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
CriticalCVSS 9.8No exploitEPSS 1%kramerav · via go2 firmwareMay 31, 2023
- CVE-2023-3346836Monitor
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation
CriticalCVSS 9.1No exploitEPSS 1%kramerav · via go2 firmwareAug 9, 2023
- CVE-2023-3346931Monitor
In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a vers
HighCVSS 7.8No exploitEPSS 0%kramerav · via go2 firmwareAug 9, 2023
- CVE-2023-3350730Monitor
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.
HighCVSS 7.5No exploitEPSS 1%kramerav · via go2 firmwareMay 31, 2023