Itarian provides on-premise and SaaS service desk and endpoint management solutions, with observed vulnerabilities concentrating in access control and security validation areas such as permission assignment, authentication checks, and session-handling practices. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Itarian over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25152HIGH The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due | Jun 9, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-25153HIGH The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low pr | Jun 9, 2022 | 7.8 | 20 | NO | NO |
CVE-2022-25151HIGH Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A | Jun 9, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Itarian.
Media articles that mention a CVE ID that affects a product developed by Itarian — matched by CVE ID, not by vendor name.