Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nch

First CVE: Nov 20, 2009Active for: 17 yearsTotal CVEs: 9

NCH Software maintains a portfolio of communication and business management applications including PBX systems, virtual telephony platforms, and customer relationship management tools. The recurring vulnerability exposure across these products centers on input-handling and information-disclosure weaknesses including path traversal, cleartext credential storage, cross-site scripting, and untrusted search-path issues, reflecting common web and system-integration challenges in this application class. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2009
16 years ago
Most Recent CVE
Jul 25, 2021
1,825 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11552MEDIUM
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied da
Jun 1, 20186.134NONO
CVE-2021-37441HIGH
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
Jul 25, 20218.827NONO
CVE-2018-11551HIGH
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists b
Jun 1, 20187.824NONO
CVE-2021-37440MEDIUM
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
Jul 25, 20216.522NONO
CVE-2021-37439MEDIUM
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
Jul 25, 20216.522NONO
CVE-2021-37469MEDIUM
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.
Jul 25, 20216.522NONO
CVE-2021-37452MEDIUM
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
Jul 25, 20215.520NONO
CVE-2021-37468LOW
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
Jul 25, 20213.316NONO
CVE-2009-4038MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) onok or
Nov 20, 20094.314NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
67%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (33.3%)
Network5 (55.6%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None6 (66.7%)
Unknown1 (11.1%)
Required2 (22.2%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None2 (22.2%)
Unknown1 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nch's Products

View all 1 CNAs →

Top CWEs