Vulnerabilities > Safensoft

DATE CVE VULNERABILITY TITLE RISK
2018-06-29 CVE-2018-13014 Insufficiently Protected Credentials vulnerability in Safensoft Enterprise Suite, Syswatch and Tpsecure
Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.2 allows the local attacker to restore the SysWatch password from the settings database and modify program settings.
local
low complexity
safensoft CWE-522
7.8
2018-06-29 CVE-2018-13013 Improper Check for Unusual or Exceptional Conditions vulnerability in Safensoft Enterprise Suite, Syswatch and Tpsecure
Improper check of unusual conditions when launching msiexec.exe in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.9 allows the local attacker to bypass a code-signing protection mechanism and install/execute an unauthorized program by modifying the system configuration and installing a forged MSI file.
local
low complexity
safensoft CWE-754
7.8
2018-06-29 CVE-2018-13012 Download of Code Without Integrity Check vulnerability in Safensoft products
Download of code with improper integrity check in snsupd.exe and upd.exe in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.12 allows the remote attacker to execute unauthorized code by substituting a forged update server.
network
high complexity
safensoft CWE-494
8.1
2018-06-12 CVE-2018-5718 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Safensoft products
Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, SoftControl/SafenSoft Enterprise Suite before version 4.4.1 allows local users to cause a denial of service (BSOD) or modify kernel-mode memory via loading of a forged DLL into an user-mode process.
local
low complexity
safensoft CWE-119
7.1