liftoffsoftware records
3 published records for vendor liftoffsoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-20184No exploit | GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.liftoffsoftware · gateone · CWE-78 | Critical9.8 | — | 2.7% | Dec 14, 2020 |
35Monitor | CVE-2020-35736Proof of concept | GateOne 1.1 allows arbitrary file download without authentication via /downloads/..liftoffsoftware · gateone · CWE-22 | High7.5 | — | 15.4% | Dec 27, 2020 |
21Monitor | CVE-2020-19003No exploit | An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances uliftoffsoftware · gate one · CWE-290 | Medium5.3 | — | 0.8% | Oct 6, 2021 |
- CVE-2020-2018440Plan
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
CriticalCVSS 9.8No exploitEPSS 3%liftoffsoftware · gateoneDec 14, 2020
- CVE-2020-3573635Monitor
GateOne 1.1 allows arbitrary file download without authentication via /downloads/..
HighCVSS 7.5Proof of conceptEPSS 15%liftoffsoftware · gateoneDec 27, 2020
- CVE-2020-1900321Monitor
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances u
MediumCVSS 5.3No exploitEPSS 1%liftoffsoftware · gate oneOct 6, 2021