Vulnerabilities > Comparex
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-12-20 | CVE-2018-19234 | Download of Code Without Integrity Check vulnerability in Comparex Miss Marple The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute arbitrary code with SYSTEM privileges via vectors related to missing update validation. | 8.8 |
2018-12-20 | CVE-2018-19233 | Use of Hard-coded Credentials vulnerability in Comparex Miss Marple COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent configuration file. | 7.8 |