Записи netwrix
21 опубликованных записей вендора netwrix.
Профиль для исследователя
- Попали в KEV
- 1 · 4,8 %
- С эксплойтом
- 1 · 4,8 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 246 дн.
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-287 Improper Authentication2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
80Срочно | CVE-2022-31199Готовый эксплойт | Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditonetwrix · auditor · CWE-502 | Критическая9,8 | KEV | 36,0 % | 7 нояб. 2022 г. |
40В плане | CVE-2025-48748Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.netwrix · directory manager · CWE-798 | Критическая10,0 | — | 0,4 % | 29 мая 2025 г. |
39Наблюдать | CVE-2025-26817Эксплойта нет | Netwrix Password Secure 9.2.0.32454 allows OS command injection.netwrix · password secure · CWE-78 | Критическая9,8 | — | 1,6 % | 3 апр. 2025 г. |
39Наблюдать | CVE-2025-26818Эксплойта нет | Netwrix Password Secure through 9.2 allows command injection.netwrix · password secure · CWE-94 | Критическая9,8 | — | 1,1 % | 3 апр. 2025 г. |
39Наблюдать | CVE-2023-41264Эксплойта нет | Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, lnetwrix · usercube · CWE-287 | Критическая9,8 | — | 1,0 % | 28 нояб. 2023 г. |
39Наблюдать | CVE-2024-36072Эксплойта нет | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logginCWE-779 | Критическая9,8 | — | 1,0 % | 27 июн. 2024 г. |
36Наблюдать | CVE-2025-48749Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Danetwrix · directory manager · CWE-201 | Критическая9,1 | — | 0,4 % | 28 мая 2025 г. |
31Наблюдать | CVE-2020-15931Proof of concept | Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domainnetwrix · account lockout examiner · CWE-200 | Высокая7,5 | — | 3,7 % | 20 окт. 2020 г. |
31Наблюдать | CVE-2019-14969Эксплойта нет | Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders.netwrix · auditor · CWE-732 | Высокая7,8 | — | 0,5 % | 12 авг. 2019 г. |
28Наблюдать | CVE-2024-36074Эксплойта нет | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the EndpoiCWE-94 | Высокая7,2 | — | 0,8 % | 27 июн. 2024 г. |
28Наблюдать | CVE-2024-36073Эксплойта нет | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowCWE-77 | Высокая7,2 | — | 0,8 % | 27 июн. 2024 г. |
26Наблюдать | CVE-2024-36075Эксплойта нет | The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due tCWE-94 | Средняя6,5 | — | 0,5 % | 27 июн. 2024 г. |
26Наблюдать | CVE-2025-48746Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critnetwrix · directory manager · CWE-287 | Средняя6,5 | — | 0,3 % | 28 мая 2025 г. |
24Наблюдать | CVE-2025-54392Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnetwrix · directory manager · CWE-79 | Средняя6,1 | — | 0,3 % | 7 авг. 2025 г. |
24Наблюдать | CVE-2025-54395Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.netwrix · directory manager · CWE-79 | Средняя6,1 | — | 0,3 % | 7 авг. 2025 г. |
21Наблюдать | CVE-2025-47748Эксплойта нет | Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.netwrix · directory manager · CWE-259 | Средняя5,3 | — | 0,3 % | 28 мая 2025 г. |
21Наблюдать | CVE-2025-54394Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to netwrix · directory manager · CWE-522 | Средняя5,3 | — | 0,3 % | 7 авг. 2025 г. |
21Наблюдать | CVE-2025-54393Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection.netwrix · directory manager · CWE-77 | Средняя5,4 | — | 0,2 % | 7 авг. 2025 г. |
21Наблюдать | CVE-2025-54396Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection.netwrix · directory manager · CWE-89 | Средняя5,4 | — | 0,2 % | 7 авг. 2025 г. |
20Наблюдать | CVE-2025-48747Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assinetwrix · directory manager · CWE-732 | Средняя5,0 | — | 0,3 % | 28 мая 2025 г. |
17Наблюдать | CVE-2025-54397Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticnetwrix · directory manager · CWE-284 | Средняя4,3 | — | 0,3 % | 7 авг. 2025 г. |
- CVE-2022-3119980Срочно
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Audito
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 36 %netwrix · auditor7 нояб. 2022 г.
- CVE-2025-4874840В плане
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %netwrix · directory manager29 мая 2025 г.
- CVE-2025-2681739Наблюдать
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %netwrix · password secure3 апр. 2025 г.
- CVE-2025-2681839Наблюдать
Netwrix Password Secure through 9.2 allows command injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %netwrix · password secure3 апр. 2025 г.
- CVE-2023-4126439Наблюдать
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, l
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %netwrix · usercube28 нояб. 2023 г.
- CVE-2024-3607239Наблюдать
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the loggin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %27 июн. 2024 г.
- CVE-2025-4874936Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Da
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %netwrix · directory manager28 мая 2025 г.
- CVE-2020-1593131Наблюдать
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %netwrix · account lockout examiner20 окт. 2020 г.
- CVE-2019-1496931Наблюдать
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %netwrix · auditor12 авг. 2019 г.
- CVE-2024-3607428Наблюдать
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoi
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %27 июн. 2024 г.
- CVE-2024-3607328Наблюдать
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadow
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %27 июн. 2024 г.
- CVE-2024-3607526Наблюдать
The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due t
СредняяCVSS 6,5Эксплойта нетEPSS 1 %27 июн. 2024 г.
- CVE-2025-4874626Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Crit
СредняяCVSS 6,5Эксплойта нетEPSS 0 %netwrix · directory manager28 мая 2025 г.
- CVE-2025-5439224Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vul
СредняяCVSS 6,1Эксплойта нетEPSS 0 %netwrix · directory manager7 авг. 2025 г.
- CVE-2025-5439524Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %netwrix · directory manager7 авг. 2025 г.
- CVE-2025-4774821Наблюдать
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %netwrix · directory manager28 мая 2025 г.
- CVE-2025-5439421Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to
СредняяCVSS 5,3Эксплойта нетEPSS 0 %netwrix · directory manager7 авг. 2025 г.
- CVE-2025-5439321Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %netwrix · directory manager7 авг. 2025 г.
- CVE-2025-5439621Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %netwrix · directory manager7 авг. 2025 г.
- CVE-2025-4874720Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assi
СредняяCVSS 5,0Эксплойта нетEPSS 0 %netwrix · directory manager28 мая 2025 г.
- CVE-2025-5439717Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authentic
СредняяCVSS 4,3Эксплойта нетEPSS 0 %netwrix · directory manager7 авг. 2025 г.