Skip to main content

Vendor archive

trms CVEs

Beta · best-effort

5 CVEs tagged to vendor trms1 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2018-18931

Published Oct 29, 2019

An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Services directory, an attacker who h…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18930

Published Oct 29, 2019

The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to ga…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18929

Published Oct 29, 2019

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13020

Published Aug 26, 2019

The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1