Netmechanica's vulnerability profile is concentrated in its NetDecision network-management and TFTP-server product line, with the observed weakness classes centered on information disclosure, path traversal, and memory-boundary handling in edge-facing services. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netmechanica over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1730HIGH Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences | May 20, 2009 | 10.0 | 76 | NO | YES |
CVE-2012-1465MEDIUM Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in a | Mar 19, 2012 | 4.3 | 46 | NO | YES |
CVE-2017-14311HIGH The Winring0x32.sys driver in NetMechanica NetDecision 5.8.2 allows local users to gain privileges via a crafted 0x9C402088 IOCTL call. | Sep 19, 2017 | 7.8 | 34 | NO | YES |
CVE-2012-1466MEDIUM The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invali | Mar 19, 2012 | 5.0 | 28 | NO | YES |
CVE-2012-1464MEDIUM Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboa | Mar 19, 2012 | 5.0 | 27 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netmechanica.
Media articles that mention a CVE ID that affects a product developed by Netmechanica — matched by CVE ID, not by vendor name.