Groundwork Monitor
Vendor:
First CVE: May 8, 2013 · Active for 13 years
15
Total CVEs
More Total CVEs than 92% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Groundwork Monitor over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2013
13 years ago
Most Recent CVE
May 8, 2013
4,827 days ago
CVE Severity & Scoring
Groundwork Monitor15 CVEs
73%
20%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown15 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown15 (100.0%)
User Interaction
None0 (0.0%)
Unknown15 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown15 (100.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3502MEDIUM monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive | May 8, 2013 | 6.5 | 63 | NO | YES |
CVE-2013-3512MEDIUM The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to read or modify configuration s | May 8, 2013 | 6.5 | 22 | NO | NO |
CVE-2013-3513MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Noma component in GroundWork Monitor Enterprise 6.7.0 allow remote attackers to hijack the authentication of unspe | May 8, 2013 | 6.8 | 21 | NO | NO |
CVE-2013-3499HIGH GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administrative privileges or access fil | May 8, 2013 | 7.5 | 21 | NO | NO |
CVE-2013-3508MEDIUM html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary comman | May 8, 2013 | 6.5 | 20 | NO | NO |
CVE-2013-3506HIGH cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execu | May 8, 2013 | 7.5 | 20 | NO | NO |
CVE-2013-3500HIGH The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/groundwork, which allows contex | May 8, 2013 | 7.5 | 20 | NO | NO |
CVE-2013-3504MEDIUM Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by l | May 8, 2013 | 5.5 | 19 | NO | NO |
CVE-2013-3510MEDIUM Multiple SQL injection vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow remote authenticated users to execute arbitrary SQL commands via (1) nedi/html/System-Export.php | May 8, 2013 | 6.5 | 18 | NO | NO |
CVE-2013-3509MEDIUM html/System-NeDi.php in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sc | May 8, 2013 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Groundwork Monitor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.7.0 | 15 | 5.9 | 5.2% | 0 | 1 |