Ipass provides mobile connectivity and remote-access solutions through products such as Ipass Open Mobile and RoamServer, with a narrow but deployed vulnerability footprint centered on code-injection weaknesses in these connectivity platforms. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipass over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0925HIGH The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperl | Jan 22, 2015 | 9.0 | 69 | NO | YES |
CVE-1999-1274MEDIUM iPass RoamServer 3.1 creates temporary files with world-writable permissions. | Dec 29, 1997 | 6.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipass.
Media articles that mention a CVE ID that affects a product developed by Ipass — matched by CVE ID, not by vendor name.