Vulnerabilities > Zpesystems

DATE CVE VULNERABILITY TITLE RISK
2023-10-28 CVE-2023-43322 Command Injection vulnerability in Zpesystems Nodegrid OS
ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.
network
low complexity
zpesystems CWE-77
8.8
2023-10-14 CVE-2023-44037 Cleartext Storage of Sensitive Information vulnerability in Zpesystems Nodegrid OS
An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component.
network
low complexity
zpesystems CWE-312
7.5