Appsanywhere develops a client-based application delivery and workspace solution that centralizes access to remote applications and resources, with its vulnerability exposure centered in the Appsanywhere Client product. The recurring weakness classes—improper privilege management, hard-coded credentials, hard-coded cryptographic keys, and sensitive information retention—reflect the authentication, credential handling, and lifecycle management demands of a client that mediates access to enterprise resources. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Appsanywhere over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41137CRITICAL Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere se | Nov 9, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-41138MEDIUM The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process. | Nov 9, 2023 | 6.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Appsanywhere.
Media articles that mention a CVE ID that affects a product developed by Appsanywhere — matched by CVE ID, not by vendor name.