Jetstream's vulnerability footprint centers on its JetSelect product and is characterized by a pattern of cryptographic and credential-handling weaknesses, including cleartext storage of sensitive information, exposure of sensitive data to unauthorized actors, insufficiently protected credentials, and use of broken or risky cryptographic algorithms. These recurrent issues reflect gaps in secure data protection and secrets management within the product's design. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jetstream over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13022CRITICAL Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). | May 14, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-13021MEDIUM The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backu | May 14, 2020 | 6.5 | 23 | NO | NO |
CVE-2019-13023MEDIUM An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non admin | May 14, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jetstream.
Media articles that mention a CVE ID that affects a product developed by Jetstream — matched by CVE ID, not by vendor name.