VYPR
Vendor

EScan

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2014-125118CriJul 25, 2025
    risk 0.64cvss epss 0.03

    A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker with a valid username to inject arbitrary…

  • CVE-2024-42919CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

  • CVE-2021-26624HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.02

    An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root…

  • CVE-2018-6203HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C.

  • CVE-2018-6202HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8.

  • CVE-2018-6201HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4.

  • CVE-2023-2875MedMay 24, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulation leads to null pointer dereference. It is possible to…