Skip to main content

Vendor archive

device42 CVEs

Beta · best-effort

6 CVEs tagged to vendor device421 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-1410

Published Aug 17, 2022

OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1401

Published Aug 17, 2022

Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive s…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-1400

Published Aug 17, 2022

Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak ses…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-1399

Published Aug 17, 2022

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitr…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-41316

Published Sep 17, 2021

The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41315

Published Sep 17, 2021

The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console appl…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1