Workforce Access
Vendor:
First CVE: Jul 19, 2022 · Active for 4 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Workforce Access over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2022
4 years ago
Most Recent CVE
Feb 29, 2024
876 days ago
CVE Severity & Scoring
Workforce Access8 CVEs
13%
75%
13%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (75.0%)
Network1 (12.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (12.5%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (75.0%)
High0 (0.0%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3258HIGH Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse. | Nov 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-0834CRITICAL Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 bef | Apr 28, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-6336HIGH Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: | Jan 16, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-6335HIGH Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access | Jan 16, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-6334HIGH Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Acces | Jan 16, 2024 | 7.8 | 22 | NO | NO |
CVE-2022-1984HIGH This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated att | Jul 19, 2022 | 7.8 | 21 | NO | NO |
CVE-2024-0068HIGH Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before | Feb 29, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-5097MEDIUM Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7. | Jan 16, 2024 | 5.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Workforce Access
Top CWEs
Versions
No cataloged versions.