Записи code42
10 опубликованных записей вендора code42.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-426 Untrusted Search Path2
- CWE-269 Improper Privilege Management2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-502 Deserialization of Untrusted Data1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2017-9830Proof of concept | Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiaticode42 · crashplan · CWE-502 | Критическая9,8 | — | 6,5 % | 27 июн. 2017 г. |
40В плане | CVE-2019-15131Эксплойта нет | In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files tocode42 · code42 · CWE-434 | Критическая9,8 | — | 1,9 % | 17 сент. 2019 г. |
35Наблюдать | CVE-2021-43269Эксплойта нет | In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config code42 · code42 · CWE-94 | Высокая8,8 | — | 1,3 % | 19 янв. 2022 г. |
35Наблюдать | CVE-2019-11553Эксплойта нет | In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organizatcode42 · code42 · CWE-269 | Высокая8,8 | — | 1,0 % | 19 июл. 2019 г. |
31Наблюдать | CVE-2018-20131Эксплойта нет | The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashpcode42 · code42 · CWE-732 | Высокая7,8 | — | 0,3 % | 2 янв. 2019 г. |
29Наблюдать | CVE-2020-12736Эксплойта нет | Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution.code42 · code42 · CWE-74 | Высокая7,2 | — | 2,0 % | 7 июл. 2020 г. |
29Наблюдать | CVE-2019-16861Эксплойта нет | Code42 server through 7.0.2 for Windows has an Untrusted Search Path.code42 · code42 · CWE-426 | Высокая7,3 | — | 0,4 % | 19 нояб. 2019 г. |
29Наблюдать | CVE-2019-16860Эксплойта нет | Code42 app through version 7.0.2 for Windows has an Untrusted Search Path.code42 · code42 · CWE-426 | Высокая7,3 | — | 0,4 % | 19 нояб. 2019 г. |
28Наблюдать | CVE-2019-11552Эксплойта нет | Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injeccode42 · code42 for enterprise · CWE-94 | Высокая7,0 | — | 0,5 % | 19 июл. 2019 г. |
22Наблюдать | CVE-2019-11551Эксплойта нет | In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a filcode42 · code42 for enterprise · CWE-269 | Средняя5,5 | — | 0,3 % | 21 авг. 2019 г. |
- CVE-2017-983041В плане
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiati
КритическаяCVSS 9,8Proof of conceptEPSS 6 %code42 · crashplan27 июн. 2017 г.
- CVE-2019-1513140В плане
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %code42 · code4217 сент. 2019 г.
- CVE-2021-4326935Наблюдать
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %code42 · code4219 янв. 2022 г.
- CVE-2019-1155335Наблюдать
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organizat
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %code42 · code4219 июл. 2019 г.
- CVE-2018-2013131Наблюдать
The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashp
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %code42 · code422 янв. 2019 г.
- CVE-2020-1273629Наблюдать
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %code42 · code427 июл. 2020 г.
- CVE-2019-1686129Наблюдать
Code42 server through 7.0.2 for Windows has an Untrusted Search Path.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %code42 · code4219 нояб. 2019 г.
- CVE-2019-1686029Наблюдать
Code42 app through version 7.0.2 for Windows has an Untrusted Search Path.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %code42 · code4219 нояб. 2019 г.
- CVE-2019-1155228Наблюдать
Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injec
ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %code42 · code42 for enterprise19 июл. 2019 г.
- CVE-2019-1155122Наблюдать
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a fil
СредняяCVSS 5,5Эксплойта нетEPSS 0 %code42 · code42 for enterprise21 авг. 2019 г.