VYPR

Reach Server

by Goverlan

CVEs (2)

  • CVE-2019-20456HigFeb 16, 2020
    risk 0.51cvss 7.8epss 0.01

    Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

  • CVE-2022-31215MedMay 20, 2022
    risk 0.42cvss 6.5epss 0.01

    In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach…