pascom records
3 published records for vendor pascom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2021-45967Proof of concept | An issue was discovered in Pascom Cloud Phone System before 7.20.x.pascom · cloud phone system · CWE-22 | Critical9.8 | — | 20.8% | Mar 18, 2022 |
41Plan | CVE-2021-45966No exploit | An issue was discovered in Pascom Cloud Phone System before 7.20.x.pascom · cloud phone system · CWE-78 | Critical9.8 | — | 6.0% | Mar 18, 2022 |
33Monitor | CVE-2021-45968Proof of concept | An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.2pascom · cloud phone system · CWE-918 | High7.5 | — | 10.4% | Mar 18, 2022 |
- CVE-2021-4596745Plan
An issue was discovered in Pascom Cloud Phone System before 7.20.x.
CriticalCVSS 9.8Proof of conceptEPSS 21%pascom · cloud phone systemMar 18, 2022
- CVE-2021-4596641Plan
An issue was discovered in Pascom Cloud Phone System before 7.20.x.
CriticalCVSS 9.8No exploitEPSS 6%pascom · cloud phone systemMar 18, 2022
- CVE-2021-4596833Monitor
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.2
HighCVSS 7.5Proof of conceptEPSS 10%pascom · cloud phone systemMar 18, 2022