Suremdm
Vendor:
First CVE: Feb 5, 2019 · Active for 7 years
6
Total CVEs
More Total CVEs than 83% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Suremdm over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 5, 2019
7 years ago
Most Recent CVE
Jul 25, 2023
1,099 days ago
CVE Severity & Scoring
Suremdm6 CVEs
50%
50%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15657HIGH An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. | Feb 5, 2019 | 7.3 | 34 | NO | YES |
CVE-2023-3897MEDIUM Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error messag | Jul 25, 2023 | 5.3 | 27 | NO | YES |
CVE-2018-15658HIGH An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be pr | Feb 5, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-15656HIGH An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email, where :email is a base6 | Feb 5, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-15659MEDIUM An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications. Cross-origin access is possible. | Feb 5, 2019 | 6.5 | 23 | NO | NO |
CVE-2018-15655MEDIUM An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible. | Feb 5, 2019 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
33.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Suremdm
Top CWEs
Versions
No cataloged versions.