Insight
Vendor:
First CVE: May 31, 2023 · Active for 3 years
10
Total CVEs
More Total CVEs than 88% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Insight over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2023
3 years ago
Most Recent CVE
May 31, 2023
1,151 days ago
CVE Severity & Scoring
Insight10 CVEs
10%
20%
60%
10%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (10.0%)
Network3 (30.0%)
Unknown0 (0.0%)
Physical1 (10.0%)
Adjacent Network5 (50.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28347CRITICAL An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, | May 31, 2023 | 9.6 | 30 | NO | NO |
CVE-2023-28353HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer, | May 31, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-28349HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This | May 31, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-28352HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can conn | May 31, 2023 | 7.4 | 23 | NO | NO |
CVE-2023-28348HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, | May 31, 2023 | 7.4 | 23 | NO | NO |
CVE-2023-28344HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots o | May 31, 2023 | 7.1 | 23 | NO | NO |
CVE-2023-28350MEDIUM An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console | May 31, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-28346HIGH An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSet | May 31, 2023 | 7.3 | 19 | NO | NO |
CVE-2023-28345MEDIUM An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint a | May 31, 2023 | 4.6 | 18 | NO | NO |
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readab | May 31, 2023 | 3.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Insight
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.0.19045 | 10 | 7.0 | 1.0% | 0 | 0 |