Platform
Vendor:
First CVE: Oct 13, 2023 · Active for 2 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 2023
2 years ago
Most Recent CVE
Mar 12, 2025
499 days ago
CVE Severity & Scoring
Platform6 CVEs
17%
67%
17%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low1 (16.7%)
High3 (50.0%)
None2 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45162CRITICAL Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.
Application of the relevant hotfix remediates this issue.
for v | Oct 13, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-45163HIGH The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a | Nov 6, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-45161HIGH The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a s | Nov 6, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-5964HIGH The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message param | Nov 6, 2023 | 7.2 | 23 | NO | NO |
CVE-2025-1683HIGH Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system | Mar 12, 2025 | 7.8 | 21 | NO | NO |
CVE-2024-7211MEDIUM The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection p | Aug 1, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.1 | 1 | 9.8 | 0.6% | 0 | 0 |
| 8.4.1.229 | 1 | 6.1 | 0.2% | 0 | 0 |
| 8.4.1 | 1 | 9.8 | 0.6% | 0 | 0 |
| 8.1.2 | 1 | 9.8 | 0.6% | 0 | 0 |
| 24.7 | 1 | 6.1 | 0.2% | 0 | 0 |
| 23.7.1.80 | 1 | 6.1 | 0.2% | 0 | 0 |
| 23.7.1 | 1 | 9.8 | 0.6% | 0 | 0 |
| 23.11.1.15 | 1 | 6.1 | 0.2% | 0 | 0 |