vasco records
2 published records for vendor vasco.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2015-7349No exploit | Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Citrix Web Interface avasco · digipass · CWE-79 | Medium6.1 | — | 1.3% | Sep 27, 2017 |
14Monitor | CVE-2013-7292No exploit | VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by enterivasco · identikey authentication server · CWE-287 | Low3.5 | — | 1.2% | Jan 13, 2014 |
- CVE-2015-734924Monitor
Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Citrix Web Interface a
MediumCVSS 6.1No exploitEPSS 1%vasco · digipassSep 27, 2017
- CVE-2013-729214Monitor
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by enteri
LowCVSS 3.5No exploitEPSS 1%vasco · identikey authentication serverJan 13, 2014