Skip to content
Noroxi

nch records

9 published records for vendor nch.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..

    HighCVSS 8.8No exploitEPSS 1%

    nch · axon pbxJul 25, 2021

  • There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.

    MediumCVSS 6.1No exploitEPSS 29%

    nch · axon pbxJun 1, 2018

  • AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a tar

    HighCVSS 7.8No exploitEPSS 2%

    nch · axon pbxJun 1, 2018

  • In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..

    MediumCVSS 6.5No exploitEPSS 1%

    nch · webdictateJul 25, 2021

  • NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..

    MediumCVSS 6.5No exploitEPSS 1%

    nch · axon pbxJul 25, 2021

  • NCH FlexiServer v6.00 suffers from a syslog?file=/..

    MediumCVSS 6.5No exploitEPSS 1%

    nch · flexiserverJul 25, 2021

  • NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configur

    MediumCVSS 5.5No exploitEPSS 0%

    nch · quorumJul 25, 2021

  • CVE-2009-4038
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrar

    MediumCVSS 4.3No exploitEPSS 2%

    nch · axon virtual pbxNov 20, 2009

  • NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.

    LowCVSS 3.3No exploitEPSS 0%

    nch · reflect customer relationship managementJul 25, 2021