Logonbox maintains a narrowly focused identity and access management product, Nervepoint Access Manager, with a limited but notable vulnerability surface centered on access control. The recurring weakness class of authorization bypass through user-controlled key reflects the fundamental risk of authentication and session-management implementations in systems handling sensitive credential operations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Logonbox over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6716CRITICAL An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Act | Mar 21, 2019 | 9.4 | 43 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Logonbox.
Media articles that mention a CVE ID that affects a product developed by Logonbox — matched by CVE ID, not by vendor name.