Automox Inc. develops endpoint management and patch-automation software deployed across enterprise environments to centralize device updates and compliance. The vendor's vulnerability profile centers on a single flagship product and recurs through access-control and permission-management weakness classes—including incorrect default permissions, improper access control, and sensitive information disclosure in logs—that reflect the privileged operational scope required of management agents. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Automox Inc. over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43326HIGH Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory. | Dec 15, 2021 | 7.8 | 36 | NO | YES |
CVE-2021-43325HIGH Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression. | Dec 15, 2021 | 7.8 | 25 | NO | NO |
CVE-2022-27904HIGH Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process. | Jul 1, 2022 | 7.0 | 24 | NO | NO |
CVE-2022-24308MEDIUM Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process. | Apr 13, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-36122HIGH The Automox Agent before 40 on Windows incorrectly sets permissions on key files. | Oct 21, 2022 | 7.8 | 19 | NO | NO |
CVE-2021-26909MEDIUM Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organiza | Apr 23, 2021 | 5.3 | 19 | NO | NO |
Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's se | Apr 23, 2021 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Automox Inc..
Media articles that mention a CVE ID that affects a product developed by Automox Inc. — matched by CVE ID, not by vendor name.