Eracent's vulnerability footprint is concentrated in a narrow set of agent-based products—including EPA, EDA, EPM, EUA, and FLW agents—that share a common exposure pattern rooted in file-system path resolution and link-following weaknesses. The recurring vulnerability classes, improper link resolution before file access and untrusted search path issues, reflect a structural susceptibility to symlink and directory-traversal attacks that can affect deployments where these agents operate with elevated privileges. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eracent over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17446HIGH An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be used to start external programs with e | Nov 22, 2019 | 7.8 | 23 | NO | NO |
CVE-2019-17445MEDIUM An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to | Nov 22, 2019 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eracent.
Media articles that mention a CVE ID that affects a product developed by Eracent — matched by CVE ID, not by vendor name.