Faronics develops a focused line of endpoint management and data protection products, including Insight, Deep Freeze, and Freezex, deployed in educational and corporate environments to control system configuration and restrict unauthorized changes. The vendor's vulnerability profile centers on application-layer and data-handling weaknesses: cross-site scripting, cleartext storage and transmission of sensitive information, path traversal, and improper resource exposure, reflecting the privileged access and configuration scope these tools maintain. A meaningful share of disclosures reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Faronics over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28347CRITICAL An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, | May 31, 2023 | 9.6 | 30 | NO | NO |
CVE-2023-28353HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer, | May 31, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-28349HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This | May 31, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-28352HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can conn | May 31, 2023 | 7.4 | 23 | NO | NO |
CVE-2023-28348HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, | May 31, 2023 | 7.4 | 23 | NO | NO |
CVE-2023-28344HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots o | May 31, 2023 | 7.1 | 23 | NO | NO |
CVE-2023-28350MEDIUM An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console | May 31, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-28346HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSet | May 31, 2023 | 7.3 | 19 | NO | NO |
CVE-2014-2382HIGH The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code | Nov 20, 2014 | 7.2 | 19 | NO | NO |
CVE-2023-28345MEDIUM An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint a | May 31, 2023 | 4.6 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Faronics.
Media articles that mention a CVE ID that affects a product developed by Faronics — matched by CVE ID, not by vendor name.