Secure Enterprise Client
Vendor:
First CVE: Sep 6, 2012 · Active for 13 years
8
Total CVEs
More Total CVEs than 87% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secure Enterprise Client over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2012
13 years ago
Most Recent CVE
Nov 26, 2025
244 days ago
CVE Severity & Scoring
Secure Enterprise Client8 CVEs
50%
38%
13%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network6 (75.0%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High0 (0.0%)
Unknown1 (12.5%)
User Interaction
None7 (87.5%)
Unknown1 (12.5%)
Required0 (0.0%)
Privileges Required
Low6 (75.0%)
High0 (0.0%)
None1 (12.5%)
Unknown1 (12.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26155CRITICAL NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability. | Nov 26, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-28872HIGH Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\N | Dec 25, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-28868HIGH Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link. | Dec 9, 2023 | 8.1 | 22 | NO | NO |
CVE-2020-11474HIGH NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant. | Jul 28, 2020 | 7.8 | 20 | NO | NO |
CVE-2010-5203MEDIUM Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 18, and Secure Client - Juniper Edition b | Sep 6, 2012 | 6.9 | 20 | NO | NO |
CVE-2023-28869MEDIUM Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link. | Dec 9, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-28870MEDIUM Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts. | Dec 9, 2023 | 6.5 | 18 | NO | NO |
CVE-2023-28871MEDIUM Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link. | Dec 9, 2023 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Secure Enterprise Client
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 13.18 | 1 | 9.8 | 0.6% | 0 | 0 |