VYPR
Vendor

Twinsoft

Products
3
CVEs
3
Across products
3
Status
Private

Products

3

Recent CVEs

3
  • CVE-2021-22646HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.

  • CVE-2021-22650HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution.

  • CVE-2023-3395MedJul 3, 2023
    risk 0.42cvss 6.5epss 0.00

    ​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The…