Faronics
Faronics Insight: vulnerabilidades y CVE
Faronics Insight tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-28353 | Alta (8.8) | 1.4% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer, enabling a variety of different… |
| CVE-2023-28352 | Alta (7.4) | 0.69% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console… |
| CVE-2023-28351 | Baja (3.3) | 0.30% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can… |
| CVE-2023-28350 | Media (6.1) | 1.1% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to… |
| CVE-2023-28349 | Alta (8.8) | 1.2% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect… |
| CVE-2023-28348 | Alta (7.4) | 0.44% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student… |
| CVE-2023-28347 | Crítica (9.6) | 2.8% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers… |
| CVE-2023-28346 | Alta (7.3) | 0.88% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual… |
| CVE-2023-28345 | Media (4.6) | 0.32% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers… |
| CVE-2023-28344 | Alta (7.1) | 0.91% | — | 31 may 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit… |