Vulnerabilities > Tsplus > Tsplus Remote Work > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-10-17 CVE-2023-27133 Incorrect Default Permissions vulnerability in Tsplus Remote Work 16.0.0.0
TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder.
network
low complexity
tsplus CWE-276
critical
9.8
2023-10-17 CVE-2023-27132 Insufficiently Protected Credentials vulnerability in Tsplus Remote Work 16.0.0.0
TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal.
network
low complexity
tsplus CWE-522
critical
9.8