Cs141
Vendor:
First CVE: Apr 27, 2020 · Active for 6 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cs141 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2020
6 years ago
Most Recent CVE
Sep 28, 2023
1,032 days ago
CVE Severity & Scoring
Cs1419 CVEs
22%
44%
33%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low3 (33.3%)
High1 (11.1%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47190CRITICAL Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute arbitrary code as root. | Mar 31, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47192HIGH Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to repl | Mar 31, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-47191HIGH Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing him to escalate privileges. | Mar 31, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-47189CRITICAL Generex UPS CS141 below 2.06 version, allows an attacker toupload a firmware file containing an incorrect configuration, in order to disrupt the normal functionality of the device. | Mar 31, 2023 | 9.1 | 27 | NO | NO |
CVE-2022-47186CRITICAL There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, without any format restriction a | Sep 28, 2023 | 9.1 | 26 | NO | NO |
CVE-2022-47188HIGH There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing | Mar 31, 2023 | 7.5 | 23 | NO | NO |
CVE-2020-11420MEDIUM UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that refere | Apr 27, 2020 | 6.5 | 22 | NO | NO |
CVE-2022-42457HIGH Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can | Oct 6, 2022 | 7.2 | 19 | NO | NO |
CVE-2022-47187MEDIUM There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When | Sep 28, 2023 | 6.1 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Cs141
Top CWEs
Versions
No cataloged versions.