Skip to main content

Vendor archive

1e CVEs

Beta · best-effort

12 CVEs tagged to vendor 1e4 Critical, 6 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-1683

Published Mar 12, 2025

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7211

Published Aug 1, 2024

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5964

Published Nov 6, 2023

The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message para…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45163

Published Nov 6, 2023

The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45161

Published Nov 6, 2023

The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45162

Published Oct 13, 2023

Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.  Application of the relevant hotfix remediates this issue. for…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45160

Published Oct 5, 2023

In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource scrip…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45159

Published Oct 5, 2023

1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junction to point to a protected dire…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27645

Published Dec 29, 2020

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote auth…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27644

Published Dec 29, 2020

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote auth…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27643

Published Dec 29, 2020

The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16268

Published Dec 29, 2020

The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to install…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1