Gwos develops GroundWork Monitor, a network and infrastructure monitoring platform that occupies a prominent role in enterprise observability and IT operations environments. The vendor's vulnerability profile centers on application-layer weaknesses endemic to web-facing monitoring interfaces: improper input validation, CSRF flaws, code injection, path traversal, and exposure of sensitive configuration data recur across its disclosures and reflect the attack surface presented by privileged, internet-accessible management tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gwos over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3502MEDIUM monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive | May 8, 2013 | 6.5 | 63 | NO | YES |
CVE-2013-3512MEDIUM The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to read or modify configuration s | May 8, 2013 | 6.5 | 22 | NO | NO |
CVE-2013-3513MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Noma component in GroundWork Monitor Enterprise 6.7.0 allow remote attackers to hijack the authentication of unspe | May 8, 2013 | 6.8 | 21 | NO | NO |
CVE-2013-3499HIGH GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administrative privileges or access fil | May 8, 2013 | 7.5 | 21 | NO | NO |
CVE-2013-3508MEDIUM html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary comman | May 8, 2013 | 6.5 | 20 | NO | NO |
CVE-2013-3506HIGH cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execu | May 8, 2013 | 7.5 | 20 | NO | NO |
CVE-2013-3500HIGH The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/groundwork, which allows contex | May 8, 2013 | 7.5 | 20 | NO | NO |
CVE-2013-3504MEDIUM Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by l | May 8, 2013 | 5.5 | 19 | NO | NO |
CVE-2013-3510MEDIUM Multiple SQL injection vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow remote authenticated users to execute arbitrary SQL commands via (1) nedi/html/System-Export.php | May 8, 2013 | 6.5 | 18 | NO | NO |
CVE-2013-3509MEDIUM html/System-NeDi.php in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sc | May 8, 2013 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gwos.
Media articles that mention a CVE ID that affects a product developed by Gwos — matched by CVE ID, not by vendor name.