VYPR
Vendor

Genian

Products
4
CVEs
7
Across products
7
Status
Private

Products

4

Recent CVEs

7
  • CVE-2021-26622CriMar 25, 2022
    risk 0.63cvss 9.6epss 0.03

    An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this…

  • CVE-2026-76142CriOct 1, 2026
    risk 0.60cvss —epss 0.00

    Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

  • CVE-2026-76146HigOct 1, 2026
    risk 0.55cvss —epss 0.02

    An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely

  • CVE-2026-76145HigOct 1, 2026
    risk 0.49cvss —epss 0.00

    An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration

  • CVE-2026-76143HigOct 1, 2026
    risk 0.47cvss —epss 0.00

    A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter.

  • CVE-2026-76147MedOct 1, 2026
    risk 0.38cvss —epss 0.00

    A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code

  • CVE-2026-76144LowOct 1, 2026
    risk 0.12cvss —epss 0.00

    An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch