Cellopoint develops email security and gateway appliances, with vulnerabilities centered on its Cellos secure email gateway product and characterized by memory-safety and access-control issues including out-of-bounds writes, buffer overflows, and path traversal flaws. These weakness classes reflect the complexity of processing and filtering email traffic at the gateway layer; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cellopoint over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9043CRITICAL Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, th | Sep 20, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-6744CRITICAL The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can | Jul 15, 2024 | 9.8 | 30 | NO | NO |
CVE-2020-17385HIGH Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the s | Aug 25, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-17384HIGH Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary | Aug 25, 2020 | 7.2 | 19 | NO | NO |
CVE-2020-17386MEDIUM Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbi | Aug 25, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cellopoint.
Media articles that mention a CVE ID that affects a product developed by Cellopoint — matched by CVE ID, not by vendor name.