Nac develops a focused network access control product line centered on its NacPremium offering, with disclosed vulnerabilities clustering around application-layer security issues including cleartext credential storage, cross-site scripting, and SQL injection. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nac over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6919CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection.
Thi | Sep 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-6921HIGH Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data.
This issue affects NACPremium: t | Sep 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-6920MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Stored XSS.
This issue a | Sep 2, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nac.
Media articles that mention a CVE ID that affects a product developed by Nac — matched by CVE ID, not by vendor name.