Nask maintains the EZD RP remote-access product, a narrowly scoped offering that has surfaced vulnerabilities centered on authorization logic and sensitive information exposure through policy misconfigurations. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nask over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7265HIGH Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, incl | Aug 7, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-7267MEDIUM Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP | Aug 7, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-7266MEDIUM Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, includi | Aug 7, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nask.
Media articles that mention a CVE ID that affects a product developed by Nask — matched by CVE ID, not by vendor name.