IOTransfer
by Iobit
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24562 | Cri | 0.71 | 9.8 | 0.53 | Jun 16, 2022 | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution. | ||
| CVE-2022-37197 | Hig | 0.54 | 7.8 | 0.01 | Nov 18, 2022 | IOBit IOTransfer V4 is vulnerable to Unquoted Service Path. |
- risk 0.71cvss 9.8epss 0.53
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
- risk 0.54cvss 7.8epss 0.01
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.