Cisofy's vulnerability profile centers on Lynis, a security auditing and hardening tool for Linux and Unix systems, with observed weaknesses clustering around file-handling and information-disclosure issues such as improper symlink resolution, exposure of sensitive data, and time-of-check time-of-use race conditions. These patterns reflect the tool's local-system access and configuration-scanning scope; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cisofy over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8108HIGH Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file. | Jun 8, 2017 | 7.8 | 24 | NO | NO |
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to | Jun 18, 2020 | 3.3 | 17 | NO | NO |
include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file. | Jun 8, 2014 | 3.3 | 16 | NO | NO |
CVE-2020-13882MEDIUM CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and | Jun 18, 2020 | 4.2 | 14 | NO | NO |
include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name. | Jun 8, 2014 | 3.3 | 12 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cisofy.
Media articles that mention a CVE ID that affects a product developed by Cisofy — matched by CVE ID, not by vendor name.