Vulnerabilities > Dorsettcontrols

DATE CVE VULNERABILITY TITLE RISK
2024-08-08 CVE-2024-39287 Unspecified vulnerability in Dorsettcontrols Infoscan 1.32/1.33/1.35
Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.
network
low complexity
dorsettcontrols
7.5
2024-08-08 CVE-2024-42408 Path Traversal vulnerability in Dorsettcontrols Infoscan 1.32/1.33/1.35
The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure.
network
high complexity
dorsettcontrols CWE-22
3.7
2024-08-08 CVE-2024-42493 Unspecified vulnerability in Dorsettcontrols Infoscan 1.32/1.33/1.35
Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login.
network
low complexity
dorsettcontrols
5.3