Deltarm develops the Delta RM remote-management platform, a narrowly scoped but notably positioned tool for device and infrastructure administration. The durable signal in its vulnerability footprint centers on authentication and access-control weaknesses, including authorization bypass, missing authorization checks, and weak password-recovery mechanisms, reflecting the security-critical nature of remote management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deltarm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44839MEDIUM An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send- | Jan 18, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-44837MEDIUM An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an admin user regarding the risk creation information in the /ris | Jan 19, 2022 | 4.3 | 18 | NO | NO |
CVE-2021-44838MEDIUM An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating the risk to access with the id parameter, it is possible for | Jan 18, 2022 | 4.3 | 18 | NO | NO |
CVE-2021-44836MEDIUM An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a | Jan 18, 2022 | 4.3 | 17 | NO | NO |
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk labels, such as Criticality and Priority Indication labels. By | Jan 18, 2022 | 2.7 | 12 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deltarm.
Media articles that mention a CVE ID that affects a product developed by Deltarm — matched by CVE ID, not by vendor name.