Auvesy-mdt
Auvesy-mdt Autosave: vulnerabilidades y CVE
Auvesy-mdt Autosave tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-32961 | Alta (7.5) | 1.3% | — | 1 abr 2022 | A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip… |
| CVE-2021-32957 | Alta (7.5) | 0.89% | — | 1 abr 2022 | A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML.… |
| CVE-2021-32953 | Crítica (9.8) | 1.2% | — | 1 abr 2022 | An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login. |
| CVE-2021-32949 | Alta (7.5) | 1.1% | — | 1 abr 2022 | An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a… |
| CVE-2021-32945 | Alta (7.5) | 0.41% | — | 1 abr 2022 | An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06. |
| CVE-2021-32937 | Alta (7.5) | 1.1% | — | 1 abr 2022 | An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a… |
| CVE-2021-32933 | Crítica (9.8) | 1.2% | — | 1 abr 2022 | An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then… |