1E

First CVE: Oct 5, 2023Active for: 3 years
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
2.7
Avg CVEs / Year
More Avg CVEs / Year than 18% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by 1E as a CNA, 100.0% affect products that 1E develops as a vendor.

100.0%
Self-reported: 8Third-party: 0

Of all the CVEs published that affect products developed by 1E, 66.7% are self-published by 1E as a CNA.

66.7%
33.3%
Self-published: 8Published by other CNAs: 4

Trends Over Time

The number and severity of CVEs published by 1E over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2023
2 years ago
Most Recent CVE
Mar 12, 2025
499 days ago

Top CVEs

All CVEs published by 1E as a CNA, regardless of affected vendor or product.

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.  Application of the relevant hotfix remediates this issue. for v
Oct 13, 20239.826NONO
The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a
Nov 6, 20237.224NONO
The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a s
Nov 6, 20237.224NONO
In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script
Oct 5, 20238.824NONO
The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message param
Nov 6, 20237.223NONO
1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junction to point to a protected direc
Oct 5, 20238.423NONO
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system
Mar 12, 20257.821NONO
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection p
Aug 1, 20246.118NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA8 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low2 (25.0%)
High3 (37.5%)
None3 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by 1E as a CNA.

Media Mentions

Media articles that mention a CVE ID published by 1E as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs