SecureauthCVEs & Vulnerabilities
2 CVEs affecting Secureauth products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
impacket 1secureauth identity provider 1
CVE-2021-31800CRITICAL
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
5 May 2021
9.8
CVSS
CVE-2020-9437MEDIUM
SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, in the same manner as XSS.
25 Jun 2020
4.8
CVSS
← PrevPage 1 / 1Next →