rangee records
4 published records for vendor rangee.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-16279No exploit | The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passedrangee · rangeeos · CWE-78 | Critical9.8 | — | 2.3% | Aug 20, 2020 |
35Monitor | CVE-2020-16282No exploit | In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user.rangee · rangeeos · CWE-78 | High8.8 | — | 0.4% | Aug 20, 2020 |
31Monitor | CVE-2020-16281No exploit | The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restricted environment andrangee · rangeeos · CWE-116 | High7.8 | — | 0.3% | Aug 20, 2020 |
22Monitor | CVE-2020-16280No exploit | Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing adminirangee · rangeeos · CWE-522 | Medium5.5 | — | 0.3% | Aug 20, 2020 |
- CVE-2020-1627940Plan
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed
CriticalCVSS 9.8No exploitEPSS 2%rangee · rangeeosAug 20, 2020
- CVE-2020-1628235Monitor
In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user.
HighCVSS 8.8No exploitEPSS 0%rangee · rangeeosAug 20, 2020
- CVE-2020-1628131Monitor
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restricted environment and
HighCVSS 7.8No exploitEPSS 0%rangee · rangeeosAug 20, 2020
- CVE-2020-1628022Monitor
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing admini
MediumCVSS 5.5No exploitEPSS 0%rangee · rangeeosAug 20, 2020