Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Landesk

First CVE: Apr 18, 2007Active for: 19 yearsTotal CVEs: 9

Landesk develops a focused suite of systems-management and endpoint-security products that operate as privileged administrative tools across enterprise infrastructure, including the Management Suite, Security Suite, and Server Manager. Its vulnerability profile reflects the exposure surface inherent to web-facing management consoles and remote-access platforms: recurrent weaknesses center on input validation, path traversal, cross-site request forgery, and cross-site scripting, alongside buffer-boundary issues that can arise in native management components. Defenders should treat Landesk administrative interfaces as high-value targets requiring strict access controls and prioritize patching, especially for internet-exposed management gateways; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Landesk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2007
19 years ago
Most Recent CVE
Sep 19, 2017
3,230 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-1674HIGH
Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535
Apr 18, 200710.082NOYES
CVE-2012-1195HIGH
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows
Feb 18, 20127.576NOYES
CVE-2012-1196MEDIUM
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary
Feb 18, 20125.065NOYES
CVE-2010-2892HIGH
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metach
Nov 15, 20108.539NOYES
CVE-2008-6195HIGH
Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via
Feb 20, 20097.829NOYES
CVE-2008-2468HIGH
Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and Server Manager 8.8 and earlier allow remote attackers to exec
Sep 18, 200810.028NONO
CVE-2014-5362HIGH
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the
Sep 19, 20177.225NONO
CVE-2014-5361MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for req
Apr 21, 20156.823NONO
CVE-2014-5360MEDIUM
Cross-site scripting (XSS) vulnerability in the admin interface in LANDESK Management Suite before 9.6 SP1 allows remote attackers to inject arbitrary web script or HTML via the AM
Feb 3, 20154.319NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
67%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (11.1%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None1 (11.1%)
Unknown8 (88.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (11.1%)
None0 (0.0%)
Unknown8 (88.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
33.3% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
55.6% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Landesk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Landesk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Landesk's Products

View all 2 CNAs →

Top CWEs