Vulnerabilities > Comparex

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-19234 Download of Code Without Integrity Check vulnerability in Comparex Miss Marple
The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute arbitrary code with SYSTEM privileges via vectors related to missing update validation.
network
low complexity
comparex CWE-494
8.8
2018-12-20 CVE-2018-19233 Use of Hard-coded Credentials vulnerability in Comparex Miss Marple
COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent configuration file.
local
low complexity
comparex CWE-798
7.8