Areal Topkapi
Products
4- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-1104 | Hig | 0.49 | 7.5 | 0.01 | Feb 22, 2024 | An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users. | ||
| CVE-2023-50356 | Med | 0.42 | 6.5 | 0.00 | Jan 31, 2024 | SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login. | ||
| CVE-2025-1434 | Med | 0.40 | 6.1 | 0.00 | Mar 11, 2025 | The Spreadsheet view is vulnerable to a XSS attack, where a remote unauthorised attacker can read a limited amount of values or DoS the affected spreadsheet. Disclosure of secrets or other system settings is not affected as well as other spreadsheets still work as expected. | ||
| CVE-2023-50357 | Med | 0.35 | 5.4 | 0.00 | Jan 31, 2024 | A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin users. |
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users.
- risk 0.42cvss 6.5epss 0.00
SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.
- risk 0.40cvss 6.1epss 0.00
The Spreadsheet view is vulnerable to a XSS attack, where a remote unauthorised attacker can read a limited amount of values or DoS the affected spreadsheet. Disclosure of secrets or other system settings is not affected as well as other spreadsheets still work as expected.
- risk 0.35cvss 5.4epss 0.00
A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin users.