Vulnerabilities > Hgiga > Ssr45 Isherlock User > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-12-31 CVE-2020-25848 Insufficiently Protected Credentials vulnerability in Hgiga products
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
network
low complexity
hgiga CWE-522
critical
10.0
2020-12-31 CVE-2020-35851 OS Command Injection vulnerability in Hgiga Msr45 Isherlock-User and Ssr45 Isherlock-User
HGiga MailSherlock does not validate specific parameters properly.
network
low complexity
hgiga CWE-78
critical
10.0