VYPR
Vendor

iTop VPN

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2024-53588HigJan 23, 2025
    risk 0.51cvss 7.8epss 0.00

    A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProgramData\iTop VPN\Downloader\vpn6.

  • CVE-2018-10642HigMay 2, 2018
    risk 0.47cvss 7.2epss 0.07

    Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the…

  • CVE-2022-31403MedJun 14, 2022
    risk 0.40cvss 6.1epss 0.02

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

  • CVE-2022-31402MedJun 10, 2022
    risk 0.40cvss 6.1epss 0.02

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

  • CVE-2024-1195MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability classified as critical was found in iTop VPN up to 4.0.0.1. Affected by this vulnerability is an unknown functionality in the library ITopVpnCallbackProcess.sys of the component IOCTL Handler. The manipulation leads to denial of service. The attack needs to be…

  • CVE-2022-24141MedJul 6, 2022
    risk 0.35cvss 5.4epss 0.01

    The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing…

  • CVE-2015-6544MedFeb 20, 2018
    risk 0.33cvss 6.1epss 0.05

    Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.