Skip to main content

Vendor archive

shimovpn CVEs

Beta · best-effort

6 CVEs tagged to vendor shimovpn0 Critical, 5 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2018-4007

Published Apr 17, 2019

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected fil…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4006

Published Apr 17, 2019

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is able to write a file anywhere…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4005

Published Apr 17, 2019

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRoutingWithCommand function. A user with local access can use this…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4004

Published Apr 17, 2019

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root user is able to kill any privil…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-4009

Published Apr 15, 2019

An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerab…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4008

Published Apr 15, 2019

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a user-supplied script argument an…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1