42Gears Mobility Systems develops mobile device management and kiosk-management solutions, including the SureMDM and SureLock platforms, which occupy a strategic role in enterprise endpoint control. The vendor's disclosed vulnerabilities center on credential and sensitive-information handling, recurrently manifesting through cleartext storage in registry and configuration, insufficiently protected credentials, and exposure of authentication data to unauthorized actors—a pattern consistent with the configuration-heavy and credential-intensive nature of MDM tooling. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 42Gears Mobility Systems Pvt Ltd over time
Of all the CVEs published by 42Gears Mobility Systems Pvt Ltd as a CNA, 100.0% affect products that 42Gears Mobility Systems Pvt Ltd develops as a vendor.
Of all the CVEs published that affect products developed by 42Gears Mobility Systems Pvt Ltd, 37.5% are self-published by 42Gears Mobility Systems Pvt Ltd as a CNA.
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15657HIGH An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. | Feb 5, 2019 | 7.3 | 34 | NO | YES |
CVE-2023-3897MEDIUM Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error messag | Jul 25, 2023 | 5.3 | 26 | NO | YES |
CVE-2018-15658HIGH An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be pr | Feb 5, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-15656HIGH An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email, where :email is a base6 | Feb 5, 2019 | 7.5 | 25 | NO | NO |
CVE-2023-2331HIGH Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the se | Apr 27, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-2335HIGH
Plaintext Password in Registry
vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve
Admin user credentials
Thi | Apr 27, 2023 | 7.5 | 23 | NO | NO |
CVE-2018-15659MEDIUM An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications. Cross-origin access is possible. | Feb 5, 2019 | 6.5 | 23 | NO | NO |
CVE-2018-15655MEDIUM An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible. | Feb 5, 2019 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 42Gears Mobility Systems Pvt Ltd.
Media articles that mention a CVE ID that affects a product developed by 42Gears Mobility Systems Pvt Ltd — matched by CVE ID, not by vendor name.