zingbox records
11 published records for vendor zingbox.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-798 Use of Hard-coded Credentials2
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-346 Origin Validation Error1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-1584No exploit | A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were zingbox · inspector · CWE-77 | Critical9.8 | — | 2.8% | Oct 9, 2019 |
39Monitor | CVE-2019-15019No exploit | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid softwzingbox · inspector · CWE-20 | Critical9.8 | — | 1.5% | Oct 9, 2019 |
39Monitor | CVE-2019-15020No exploit | A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softwzingbox · inspector · CWE-346 | Critical9.8 | — | 0.9% | Oct 9, 2019 |
36Monitor | CVE-2019-15014No exploit | A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execuzingbox · inspector · CWE-78 | High8.8 | — | 2.3% | Oct 9, 2019 |
35Monitor | CVE-2019-15016No exploit | An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitizzingbox · inspector · CWE-89 | High8.8 | — | 1.2% | Oct 9, 2019 |
33Monitor | CVE-2019-15017No exploit | The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network.zingbox · inspector · CWE-798 | High8.4 | — | 0.4% | Oct 9, 2019 |
33Monitor | CVE-2019-15015No exploit | In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system szingbox · inspector · CWE-798 | High8.4 | — | 0.4% | Oct 9, 2019 |
30Monitor | CVE-2019-15018No exploit | A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Izingbox · inspector · CWE-306 | High7.5 | — | 1.2% | Oct 9, 2019 |
30Monitor | CVE-2019-15022No exploit | A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoozingbox · inspector · CWE-290 | High7.5 | — | 1.1% | Oct 9, 2019 |
30Monitor | CVE-2019-15023No exploit | A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being zingbox · inspector · CWE-312 | High7.5 | — | 0.8% | Oct 9, 2019 |
21Monitor | CVE-2019-15021No exploit | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instanceszingbox · inspector · CWE-918 | Medium5.3 | — | 1.0% | Oct 9, 2019 |
- CVE-2019-158440Plan
A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were
CriticalCVSS 9.8No exploitEPSS 3%zingbox · inspectorOct 9, 2019
- CVE-2019-1501939Monitor
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid softw
CriticalCVSS 9.8No exploitEPSS 1%zingbox · inspectorOct 9, 2019
- CVE-2019-1502039Monitor
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softw
CriticalCVSS 9.8No exploitEPSS 1%zingbox · inspectorOct 9, 2019
- CVE-2019-1501436Monitor
A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execu
HighCVSS 8.8No exploitEPSS 2%zingbox · inspectorOct 9, 2019
- CVE-2019-1501635Monitor
An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitiz
HighCVSS 8.8No exploitEPSS 1%zingbox · inspectorOct 9, 2019
- CVE-2019-1501733Monitor
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network.
HighCVSS 8.4No exploitEPSS 0%zingbox · inspectorOct 9, 2019
- CVE-2019-1501533Monitor
In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system s
HighCVSS 8.4No exploitEPSS 0%zingbox · inspectorOct 9, 2019
- CVE-2019-1501830Monitor
A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the I
HighCVSS 7.5No exploitEPSS 1%zingbox · inspectorOct 9, 2019
- CVE-2019-1502230Monitor
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoo
HighCVSS 7.5No exploitEPSS 1%zingbox · inspectorOct 9, 2019
- CVE-2019-1502330Monitor
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being
HighCVSS 7.5No exploitEPSS 1%zingbox · inspectorOct 9, 2019
- CVE-2019-1502121Monitor
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances
MediumCVSS 5.3No exploitEPSS 1%zingbox · inspectorOct 9, 2019