Konzept Ix maintains a focused product line centered on PublixOne, a narrowly scoped offering that has attracted vulnerability disclosures despite its limited footprint. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Konzept Ix over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27179CRITICAL konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens. | Oct 27, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-27183CRITICAL A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, esca | Oct 27, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-27180HIGH konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter. | Oct 27, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-27182MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_j | Oct 27, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-27181MEDIUM A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configurat | Oct 27, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Konzept Ix.
Media articles that mention a CVE ID that affects a product developed by Konzept Ix — matched by CVE ID, not by vendor name.