VYPR

DupScout

by Flexense

CVEs (4)

  • CVE-2017-13696CriJan 24, 2018
    risk 0.73cvss 9.8epss 0.78

    A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server…

  • CVE-2020-29659CriDec 9, 2020
    risk 0.64cvss 9.8epss 0.05

    A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.

  • CVE-2021-47806HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject…

  • CVE-2018-10566MedMay 2, 2018
    risk 0.40cvss 6.1epss 0.01

    XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7.