DupScout
by Flexense
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-13696 | Cri | 0.73 | 9.8 | 0.78 | Jan 24, 2018 | A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server… | ||
| CVE-2020-29659 | Cri | 0.64 | 9.8 | 0.05 | Dec 9, 2020 | A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack. | ||
| CVE-2021-47806 | Hig | 0.51 | 7.8 | 0.00 | Jan 16, 2026 | Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject… | ||
| CVE-2018-10566 | Med | 0.40 | 6.1 | 0.01 | May 2, 2018 | XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7. |
- risk 0.73cvss 9.8epss 0.78
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server…
- risk 0.64cvss 9.8epss 0.05
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
- risk 0.51cvss 7.8epss 0.00
Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject…
- risk 0.40cvss 6.1epss 0.01
XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7.