Embrace

Vendor:

First CVE: Apr 19, 2024 · Active for 2 years

8
Total CVEs
More Total CVEs than 87% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Embrace over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 19, 2024
2 years ago
Most Recent CVE
Aug 20, 2024
707 days ago

CVE Severity & Scoring

Embrace8 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be s
Aug 20, 20248.824NONO
An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Apr 19, 20247.520NONO
An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.
Apr 19, 20247.520NONO
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration o
May 21, 20246.519NONO
An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary we
May 21, 20246.118NONO
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a
May 21, 20245.317NONO
An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server.
May 21, 20245.317NONO
An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows
May 23, 20244.116NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Embrace

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6.486.40.5%00