Dorsettcontrols has a narrowly scoped vulnerability footprint centered on its InfoScan product, with observed disclosures clustering around information-disclosure risks and path-traversal weaknesses. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dorsettcontrols over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-39287HIGH Dorsett Controls Central Server update server has potential information
leaks with an unprotected file that contains passwords and API keys. | Aug 8, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-42493MEDIUM Dorsett Controls InfoScan is vulnerable due to a leak of possible
sensitive information through the response headers and the rendered
JavaScript prior to user login. | Aug 8, 2024 | 5.3 | 17 | NO | NO |
The InfoScan client download page can be intercepted with a proxy, to
expose filenames located on the system, which could lead to additional
information exposure. | Aug 8, 2024 | 3.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dorsettcontrols.
Media articles that mention a CVE ID that affects a product developed by Dorsettcontrols — matched by CVE ID, not by vendor name.