VYPR
Vendor

Flowmon

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2024-2389CriApr 2, 2024
    risk 0.76cvss 10.0epss 0.93

    In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

  • CVE-2023-26101HigApr 21, 2023
    risk 0.49cvss 7.5epss 0.01

    In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vulnerability to retrieve files on the Flowmon appliance's local filesystem.

  • CVE-2023-26100MedApr 21, 2023
    risk 0.40cvss 6.1epss 0.00

    In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could leverage a reflected XSS vulnerability to execute arbitrary code within the context of a Flowmon user's web browser.