NCH Software maintains a portfolio of communication and business management applications including PBX systems, virtual telephony platforms, and customer relationship management tools. The recurring vulnerability exposure across these products centers on input-handling and information-disclosure weaknesses including path traversal, cleartext credential storage, cross-site scripting, and untrusted search-path issues, reflecting common web and system-integration challenges in this application class. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nch over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11552MEDIUM There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied da | Jun 1, 2018 | 6.1 | 34 | NO | NO |
CVE-2021-37441HIGH NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring. | Jul 25, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-11551HIGH AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists b | Jun 1, 2018 | 7.8 | 24 | NO | NO |
CVE-2021-37440MEDIUM NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring. | Jul 25, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-37439MEDIUM NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability. | Jul 25, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-37469MEDIUM In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem. | Jul 25, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-37452MEDIUM NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files. | Jul 25, 2021 | 5.5 | 20 | NO | NO |
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files. | Jul 25, 2021 | 3.3 | 16 | NO | NO |
CVE-2009-4038MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) onok or | Nov 20, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nch.
Media articles that mention a CVE ID that affects a product developed by Nch — matched by CVE ID, not by vendor name.