1E is a niche endpoint and systems-management platform vendor whose vulnerability footprint centers on a client and platform product stack that bridges IT operational control and device configuration. The recurring exposure involves input-validation weaknesses, file-access and path-resolution flaws, and privilege-boundary issues characteristic of software that must interact with the filesystem and execute with elevated context. Defenders managing 1E deployments should monitor advisories closely for configuration and boundary-validation issues; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 1E over time
Of all the CVEs published by 1E as a CNA, 100.0% affect products that 1E develops as a vendor.
Of all the CVEs published that affect products developed by 1E, 66.7% are self-published by 1E as a CNA.
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45162CRITICAL Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.
Application of the relevant hotfix remediates this issue.
for v | Oct 13, 2023 | 9.8 | 26 | NO | NO |
CVE-2020-27645HIGH The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authe | Dec 29, 2020 | 8.8 | 25 | NO | NO |
CVE-2023-45163HIGH The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a | Nov 6, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-45161HIGH The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a s | Nov 6, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-45160HIGH In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script | Oct 5, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-5964HIGH The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message param | Nov 6, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-45159HIGH 1E Client installer can perform arbitrary file deletion on protected files.
A non-privileged user could provide a symbolic link or Windows junction to point to a protected direc | Oct 5, 2023 | 8.4 | 23 | NO | NO |
CVE-2020-27644HIGH The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authe | Dec 29, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-16268HIGH The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installa | Dec 29, 2020 | 8.8 | 22 | NO | NO |
CVE-2025-1683HIGH Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system | Mar 12, 2025 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 1E.
Media articles that mention a CVE ID that affects a product developed by 1E — matched by CVE ID, not by vendor name.