Goverlan develops remote-access and systems-management software focused on enterprise administrative capabilities, with vulnerabilities observed across its client agent, console, and server components. The durable signal centers on path-handling and search-path configuration issues that reflect the trust-boundary complexity inherent to privileged administrative tooling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goverlan over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20456HIGH Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Lo | Feb 16, 2020 | 7.8 | 23 | NO | NO |
CVE-2022-31215MEDIUM In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules | May 20, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goverlan.
Media articles that mention a CVE ID that affects a product developed by Goverlan — matched by CVE ID, not by vendor name.