VYPR
Vendor

Claroty

Products
5
CVEs
5
Across products
6
Status
Private

Products

5

Recent CVEs

5
  • CVE-2023-33371CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.

  • CVE-2025-54603MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.01

    An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

  • CVE-2021-32958MedMay 23, 2022
    risk 0.36cvss 5.5epss 0.00

    Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user…

  • CVE-2023-49900CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.01

    An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

  • CVE-2023-49899CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.00

    An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.