Bund's vulnerability footprint centers on a small portfolio of specialized software products, with exposure centered in its BKG Professional NTripcaster and de.fac2 offerings and rooted in application-layer weakness classes including improper input validation, cross-site scripting, and missing authentication controls. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bund over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42982HIGH BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be | Nov 17, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-33172MEDIUM de.fac2 1.34 allows bypassing the User Presence protection mechanism when there is malware on the victim's PC. | Aug 24, 2022 | 5.5 | 20 | NO | NO |
CVE-2023-3034MEDIUM Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44 | Jun 28, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bund.
Media articles that mention a CVE ID that affects a product developed by Bund — matched by CVE ID, not by vendor name.