Записи nch
9 опубликованных записей вендора nch.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-426 Untrusted Search Path1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2021-37441Эксплойта нет | NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..nch · axon pbx · CWE-22 | Высокая8,8 | — | 1,5 % | 25 июл. 2021 г. |
33Наблюдать | CVE-2018-11552Эксплойта нет | There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.nch · axon pbx · CWE-79 | Средняя6,1 | — | 28,6 % | 1 июн. 2018 г. |
32Наблюдать | CVE-2018-11551Эксплойта нет | AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a tarnch · axon pbx · CWE-426 | Высокая7,8 | — | 2,5 % | 1 июн. 2018 г. |
26Наблюдать | CVE-2021-37469Эксплойта нет | In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..nch · webdictate · CWE-22 | Средняя6,5 | — | 1,2 % | 25 июл. 2021 г. |
26Наблюдать | CVE-2021-37440Эксплойта нет | NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..nch · axon pbx · CWE-22 | Средняя6,5 | — | 1,2 % | 25 июл. 2021 г. |
26Наблюдать | CVE-2021-37439Эксплойта нет | NCH FlexiServer v6.00 suffers from a syslog?file=/..nch · flexiserver · CWE-22 | Средняя6,5 | — | 1,2 % | 25 июл. 2021 г. |
22Наблюдать | CVE-2021-37452Эксплойта нет | NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configurnch · quorum · CWE-312 | Средняя5,5 | — | 0,3 % | 25 июл. 2021 г. |
18Наблюдать | CVE-2009-4038Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrarnch · axon virtual pbx · CWE-79 | Средняя4,3 | — | 2,4 % | 20 нояб. 2009 г. |
13Наблюдать | CVE-2021-37468Эксплойта нет | NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.nch · reflect customer relationship management · CWE-312 | Низкая3,3 | — | 0,2 % | 25 июл. 2021 г. |
- CVE-2021-3744135Наблюдать
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nch · axon pbx25 июл. 2021 г.
- CVE-2018-1155233Наблюдать
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.
СредняяCVSS 6,1Эксплойта нетEPSS 29 %nch · axon pbx1 июн. 2018 г.
- CVE-2018-1155132Наблюдать
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a tar
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %nch · axon pbx1 июн. 2018 г.
- CVE-2021-3746926Наблюдать
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..
СредняяCVSS 6,5Эксплойта нетEPSS 1 %nch · webdictate25 июл. 2021 г.
- CVE-2021-3744026Наблюдать
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..
СредняяCVSS 6,5Эксплойта нетEPSS 1 %nch · axon pbx25 июл. 2021 г.
- CVE-2021-3743926Наблюдать
NCH FlexiServer v6.00 suffers from a syslog?file=/..
СредняяCVSS 6,5Эксплойта нетEPSS 1 %nch · flexiserver25 июл. 2021 г.
- CVE-2021-3745222Наблюдать
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configur
СредняяCVSS 5,5Эксплойта нетEPSS 0 %nch · quorum25 июл. 2021 г.
- CVE-2009-403818Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrar
СредняяCVSS 4,3Эксплойта нетEPSS 2 %nch · axon virtual pbx20 нояб. 2009 г.
- CVE-2021-3746813Наблюдать
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %nch · reflect customer relationship management25 июл. 2021 г.