Vulnerabilities > NPS Project

DATE CVE VULNERABILITY TITLE RISK
2022-10-06 CVE-2022-40494 Improper Authentication vulnerability in NPS Project NPS
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.
network
low complexity
nps-project CWE-287
critical
9.8
2019-08-16 CVE-2019-15119 Incorrect Permission Assignment for Critical Resource vulnerability in NPS Project NPS
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
5.8