ncp-e records
9 published records for vendor ncp-e.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')5
- CWE-276 Incorrect Default Permissions1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-426 Untrusted Search Path1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-26155No exploit | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.ncp-e · ncp secure entry client · CWE-426 | Critical9.8 | — | 0.6% | Nov 26, 2025 |
35Monitor | CVE-2023-28872No exploit | Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a syncp-e · secure enterprise client · CWE-59 | High8.8 | — | 0.8% | Dec 25, 2023 |
32Monitor | CVE-2023-28868No exploit | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creatinncp-e · secure enterprise client · CWE-59 | High8.1 | — | 0.9% | Dec 9, 2023 |
32Monitor | CVE-2017-17023No exploit | The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com).ncp-e · ncp secure entry client · CWE-345 | High8.1 | — | 0.6% | Apr 9, 2019 |
31Monitor | CVE-2020-11474No exploit | NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.ncp-e · secure enterprise client · CWE-59 | High7.8 | — | 0.5% | Jul 28, 2020 |
27Monitor | CVE-2010-5203No exploit | Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 1ncp-e · secure client | Medium6.9 | — | 0.3% | Sep 6, 2012 |
26Monitor | CVE-2023-28869No exploit | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating systemncp-e · secure enterprise client · CWE-59 | Medium6.5 | — | 0.8% | Dec 9, 2023 |
26Monitor | CVE-2023-28870No exploit | Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files ncp-e · secure enterprise client · CWE-276 | Medium6.5 | — | 0.7% | Dec 9, 2023 |
17Monitor | CVE-2023-28871No exploit | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creancp-e · secure enterprise client · CWE-59 | Medium4.3 | — | 0.6% | Dec 9, 2023 |
- CVE-2025-2615539Monitor
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%ncp-e · ncp secure entry clientNov 26, 2025
- CVE-2023-2887235Monitor
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a sy
HighCVSS 8.8No exploitEPSS 1%ncp-e · secure enterprise clientDec 25, 2023
- CVE-2023-2886832Monitor
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creatin
HighCVSS 8.1No exploitEPSS 1%ncp-e · secure enterprise clientDec 9, 2023
- CVE-2017-1702332Monitor
The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com).
HighCVSS 8.1No exploitEPSS 1%ncp-e · ncp secure entry clientApr 9, 2019
- CVE-2020-1147431Monitor
NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
HighCVSS 7.8No exploitEPSS 1%ncp-e · secure enterprise clientJul 28, 2020
- CVE-2010-520327Monitor
Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 1
MediumCVSS 6.9No exploitEPSS 0%ncp-e · secure clientSep 6, 2012
- CVE-2023-2886926Monitor
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system
MediumCVSS 6.5No exploitEPSS 1%ncp-e · secure enterprise clientDec 9, 2023
- CVE-2023-2887026Monitor
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files
MediumCVSS 6.5No exploitEPSS 1%ncp-e · secure enterprise clientDec 9, 2023
- CVE-2023-2887117Monitor
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by crea
MediumCVSS 4.3No exploitEPSS 1%ncp-e · secure enterprise clientDec 9, 2023