VYPR

airPASS

by NetVision Information

CVEs (5)

  • CVE-2025-0456CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.

  • CVE-2025-0455CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2025-0457HigJan 16, 2025
    risk 0.57cvss 8.8epss 0.02

    The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.

  • CVE-2024-3776Apr 15, 2024
    risk 0.00cvss epss 0.00

    The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.

  • CVE-2023-48383Jan 15, 2024
    risk 0.00cvss epss 0.00

    NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.