Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Faronics

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 12
31.7
VTI Score
Medium

Faronics develops a focused line of endpoint management and data protection products, including Insight, Deep Freeze, and Freezex, deployed in educational and corporate environments to control system configuration and restrict unauthorized changes. The vendor's vulnerability profile centers on application-layer and data-handling weaknesses: cross-site scripting, cleartext storage and transmission of sensitive information, path traversal, and improper resource exposure, reflecting the privileged access and configuration scope these tools maintain. A meaningful share of disclosures reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Faronics over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
May 31, 2023
1,150 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-28347CRITICAL
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console,
May 31, 20239.630NONO
CVE-2023-28353HIGH
An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer,
May 31, 20238.828NONO
CVE-2023-28349HIGH
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This
May 31, 20238.827NONO
CVE-2023-28352HIGH
An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can conn
May 31, 20237.423NONO
CVE-2023-28348HIGH
An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher,
May 31, 20237.423NONO
CVE-2023-28344HIGH
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots o
May 31, 20237.123NONO
CVE-2023-28350MEDIUM
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console
May 31, 20236.121NONO
CVE-2023-28346HIGH
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSet
May 31, 20237.319NONO
CVE-2014-2382HIGH
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code
Nov 20, 20147.219NONO
CVE-2023-28345MEDIUM
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint a
May 31, 20234.618NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
17%
17%
58%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (8.3%)
Network3 (25.0%)
Unknown2 (16.7%)
Physical1 (8.3%)
Adjacent Network5 (41.7%)
Attack Complexity
Low9 (75.0%)
High1 (8.3%)
Unknown2 (16.7%)
User Interaction
None8 (66.7%)
Unknown2 (16.7%)
Required2 (16.7%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None8 (66.7%)
Unknown2 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Faronics.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Faronics — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Faronics's Products

View all 1 CNAs →

Top CWEs