VYPR

Stealth

by Unisys

CVEs (8)

  • CVE-2020-12053CriJun 22, 2020
    risk 0.64cvss 9.8epss 0.01

    In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.

  • CVE-2021-3141HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.00

    In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration.

  • CVE-2020-24620HigOct 1, 2020
    risk 0.51cvss 7.8epss 0.00

    Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials.

  • CVE-2018-6592HigFeb 19, 2018
    risk 0.51cvss 7.8epss 0.00

    Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by leveraging improper cleanup of memory used for negotiation key storage.

  • CVE-2024-23758HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.log file.

  • CVE-2019-18193HigFeb 3, 2020
    risk 0.49cvss 7.5epss 0.00

    In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 and 5.0.013.0.

  • CVE-2021-35056MedJul 15, 2021
    risk 0.44cvss 6.7epss 0.00

    Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.

  • CVE-2021-28492MedApr 20, 2021
    risk 0.32cvss 4.9epss 0.01

    Unisys Stealth (core) 5.x before 5.0.048.0, 5.1.x before 5.1.017.0, and 6.x before 6.0.037.0 stores passwords in a recoverable format.