Ericom specializes in secure remote-access and web-connectivity solutions, with its vulnerability profile concentrated in products such as Access Server, AccessNow Server, and PowerTerm WebConnect that mediate browser-based and terminal access to enterprise resources. The recurring signal centers on input-handling and memory-safety issues, including cross-site scripting, buffer-boundary violations, and server-side request forgery, which are typical of web-facing gateway and proxy architectures. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ericom over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3913HIGH Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non-existent file. | Jun 4, 2014 | 10.0 | 76 | NO | YES |
CVE-2022-29152MEDIUM The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page. | Apr 28, 2022 | 6.1 | 21 | NO | NO |
CVE-2020-24548MEDIUM Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" erro | Aug 26, 2020 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ericom.
Media articles that mention a CVE ID that affects a product developed by Ericom — matched by CVE ID, not by vendor name.