Helpsystems develops a focused portfolio of security and administrative tools including the widely used Cobalt Strike adversary-simulation platform, managed file-transfer solutions, and data-classification products that sit in critical operational and security functions. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a strong, recurring history of confirmed in-the-wild exploitation, reflecting the high-value targets that rely on these tools and the urgency defenders place on patching them. The exposure recurs through weakness classes including resource-exhaustion flaws, authentication bypasses, path traversal, output-encoding defects, and cross-site scripting, which span both the native code and web-facing surfaces of this product family. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Helpsystems over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39197MEDIUM An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To ex | Sep 22, 2022 | 6.1 | 81 | YES | NO |
CVE-2022-42948CRITICAL Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the C | Mar 24, 2023 | 9.8 | 70 | YES | NO |
CVE-2018-20764CRITICAL A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege esca | Feb 8, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-36798HIGH A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block b | Aug 9, 2021 | 7.5 | 27 | NO | NO |
CVE-2022-23317HIGH CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL. | Feb 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-46830MEDIUM A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an | Jul 27, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-43708MEDIUM The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode. | Apr 21, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Helpsystems.
Media articles that mention a CVE ID that affects a product developed by Helpsystems — matched by CVE ID, not by vendor name.