Cynet develops endpoint and network detection and response products, notably its Cynet 360 platform and associated client agents, which span a narrow but strategically positioned security software portfolio. The observed vulnerability pattern centers on insufficient information entries and improper privilege escalation in these agent-based components, reflecting the elevated access requirements typical of security monitoring software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cynet Security Inc. over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27969MEDIUM Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of decoy users via a crafted GET request sent to /WebApp/DeceptionUser/GetAllDeceptionUsers. | Sep 8, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-27968MEDIUM Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of monitored files and profiles via a crafted GET request sent to /WebApp/SettingsFileMonitor/Ge | Sep 8, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-27967MEDIUM Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a crafted GET request sent to /WebApp/SettingsExclusion/GetEx | Sep 8, 2022 | 5.3 | 20 | NO | NO |
CVE-2023-27247MEDIUM Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokens. | Mar 28, 2023 | 4.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cynet Security Inc..
Media articles that mention a CVE ID that affects a product developed by Cynet Security Inc. — matched by CVE ID, not by vendor name.