Vulnerabilities
Vulnerable Software
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
CVSS Score
2.5
EPSS Score
0.001
Published
2024-10-14
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
CVSS Score
5.7
EPSS Score
0.005
Published
2024-05-18
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
CVSS Score
5.9
EPSS Score
0.003
Published
2024-05-18
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-05-17
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-12-16
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-12-16


Contact Us

Shodan ® - All rights reserved