R Seenet
Vendor:
First CVE: Oct 20, 2020 · Active for 5 years
40
Total CVEs
More Total CVEs than 98% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact R Seenet over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2020
5 years ago
Most Recent CVE
Oct 18, 2023
1,013 days ago
CVE Severity & Scoring
R Seenet40 CVEs
63%
23%
15%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (7.5%)
Network37 (92.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None35 (87.5%)
Unknown0 (0.0%)
Required5 (12.5%)
Privileges Required
Low22 (55.0%)
High5 (12.5%)
None13 (32.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21805CRITICAL An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrar | Aug 5, 2021 | 9.8 | 79 | NO | YES |
CVE-2021-21801MEDIUM This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a v | Jul 16, 2021 | 6.1 | 67 | NO | YES |
CVE-2023-5642CRITICAL Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information. | Oct 18, 2023 | 9.8 | 38 | NO | NO |
CVE-2021-21799MEDIUM Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can | Jul 16, 2021 | 6.1 | 38 | NO | YES |
CVE-2021-21800MEDIUM Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can le | Jul 16, 2021 | 6.1 | 37 | NO | YES |
CVE-2021-21802MEDIUM This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a v | Jul 16, 2021 | 6.1 | 36 | NO | YES |
CVE-2021-21803MEDIUM This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a v | Jul 16, 2021 | 6.1 | 34 | NO | YES |
CVE-2022-3386CRITICAL
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer an | Oct 27, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-21924MEDIUM A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated | Dec 22, 2021 | 6.5 | 32 | NO | NO |
CVE-2022-3385CRITICAL
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote cod | Oct 27, 2022 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
15.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For R Seenet
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4.23 | 1 | 9.8 | 16.7% | 0 | 0 |
| 2.4.15 | 26 | 6.7 | 1.8% | 0 | 0 |
| 2.4.12 | 7 | 7.2 | 25.9% | 0 | 6 |