Записи adremsoft
8 опубликованных записей вендора adremsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-522 Insufficiently Protected Credentials1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-14482Эксплойта нет | AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-798 | Критическая9,8 | — | 1,8 % | 16 дек. 2020 г. |
39Наблюдать | CVE-2019-14480Эксплойта нет | AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication adremsoft · netcrunch · CWE-200 | Критическая9,8 | — | 1,1 % | 16 дек. 2020 г. |
36Наблюдать | CVE-2019-14479Эксплойта нет | AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution.adremsoft · netcrunch · CWE-78 | Высокая8,8 | — | 4,2 % | 16 дек. 2020 г. |
36Наблюдать | CVE-2019-14483Эксплойта нет | AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure.adremsoft · netcrunch | Высокая8,8 | — | 1,8 % | 16 дек. 2020 г. |
26Наблюдать | CVE-2019-14476Эксплойта нет | AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.adremsoft · netcrunch · CWE-918 | Средняя6,5 | — | 0,8 % | 16 дек. 2020 г. |
22Наблюдать | CVE-2019-14477Эксплойта нет | AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passworadremsoft · netcrunch · CWE-522 | Средняя5,5 | — | 0,3 % | 16 дек. 2020 г. |
21Наблюдать | CVE-2019-14478Эксплойта нет | AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-79 | Средняя5,4 | — | 0,6 % | 16 дек. 2020 г. |
21Наблюдать | CVE-2019-14481Эксплойта нет | AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client.adremsoft · netcrunch · CWE-352 | Средняя5,4 | — | 0,4 % | 16 дек. 2020 г. |
- CVE-2019-1448240В плане
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %adremsoft · netcrunch16 дек. 2020 г.
- CVE-2019-1448039Наблюдать
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %adremsoft · netcrunch16 дек. 2020 г.
- CVE-2019-1447936Наблюдать
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %adremsoft · netcrunch16 дек. 2020 г.
- CVE-2019-1448336Наблюдать
AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %adremsoft · netcrunch16 дек. 2020 г.
- CVE-2019-1447626Наблюдать
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %adremsoft · netcrunch16 дек. 2020 г.
- CVE-2019-1447722Наблюдать
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwor
СредняяCVSS 5,5Эксплойта нетEPSS 0 %adremsoft · netcrunch16 дек. 2020 г.
- CVE-2019-1447821Наблюдать
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %adremsoft · netcrunch16 дек. 2020 г.
- CVE-2019-1448121Наблюдать
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %adremsoft · netcrunch16 дек. 2020 г.