Vulnerabilities > Dorsettcontrols
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-08 | CVE-2024-39287 | Unspecified vulnerability in Dorsettcontrols Infoscan 1.32/1.33/1.35 Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys. | 7.5 |
2024-08-08 | CVE-2024-42408 | Path Traversal vulnerability in Dorsettcontrols Infoscan 1.32/1.33/1.35 The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure. | 3.7 |
2024-08-08 | CVE-2024-42493 | Unspecified vulnerability in Dorsettcontrols Infoscan 1.32/1.33/1.35 Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login. | 5.3 |