Pascom develops a cloud-based phone system platform, and its disclosed vulnerabilities center on input-handling and access-control issues including path traversal, OS command injection, and server-side request forgery that are characteristic of web-facing communication services. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pascom over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45967CRITICAL An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, | Mar 18, 2022 | 9.8 | 53 | NO | YES |
CVE-2021-45968HIGH An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint | Mar 18, 2022 | 7.5 | 40 | NO | YES |
CVE-2021-45966CRITICAL An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shel | Mar 18, 2022 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pascom.
Media articles that mention a CVE ID that affects a product developed by Pascom — matched by CVE ID, not by vendor name.