Vulnerabilities
Vulnerable Software
Hammock:  Security Vulnerabilities
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.
CVSS Score
9.8
EPSS Score
0.07
Published
2022-04-28
Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service".
CVSS Score
6.5
EPSS Score
0.008
Published
2017-07-17
SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service".
CVSS Score
6.3
EPSS Score
0.003
Published
2017-07-17


Contact Us

Shodan ® - All rights reserved