Agent
by Automox
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43326 | Hig | 0.54 | 7.8 | 0.01 | Dec 15, 2021 | Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory. | ||
| CVE-2022-36122 | Hig | 0.51 | 7.8 | 0.00 | Oct 21, 2022 | The Automox Agent before 40 on Windows incorrectly sets permissions on key files. | ||
| CVE-2021-43325 | Hig | 0.51 | 7.8 | 0.00 | Dec 15, 2021 | Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression. | ||
| CVE-2022-27904 | Hig | 0.46 | 7.0 | 0.00 | Jul 1, 2022 | Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process. | ||
| CVE-2022-24308 | Med | 0.36 | 5.5 | 0.00 | Apr 13, 2022 | Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process. | ||
| CVE-2021-26909 | Low | 0.24 | 3.7 | 0.01 | Apr 23, 2021 | Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent. | ||
| CVE-2021-26908 | Low | 0.21 | 3.3 | 0.00 | Apr 23, 2021 | Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent. |
- risk 0.54cvss 7.8epss 0.01
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
- risk 0.51cvss 7.8epss 0.00
The Automox Agent before 40 on Windows incorrectly sets permissions on key files.
- risk 0.51cvss 7.8epss 0.00
Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.
- risk 0.46cvss 7.0epss 0.00
Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.
- risk 0.36cvss 5.5epss 0.00
Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process.
- risk 0.24cvss 3.7epss 0.01
Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.
- risk 0.21cvss 3.3epss 0.00
Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.