Pacsone Server
Vendor:
First CVE: Sep 30, 2020 · Active for 5 years
7
Total CVEs
More Total CVEs than 83% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pacsone Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2020
5 years ago
Most Recent CVE
Feb 3, 2021
1,997 days ago
CVE Severity & Scoring
Pacsone Server7 CVEs
29%
43%
29%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low3 (42.9%)
High0 (0.0%)
None4 (57.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29165CRITICAL PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges. | Feb 3, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-29164MEDIUM PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS). | Feb 3, 2021 | 6.1 | 27 | NO | YES |
CVE-2020-12870CRITICAL RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page. | Sep 30, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-29166HIGH PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure. | Feb 3, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-29163HIGH PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection. | Feb 3, 2021 | 8.8 | 22 | NO | NO |
CVE-2020-12715HIGH RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control. | Sep 30, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-12869MEDIUM RainbowFish PacsOne Server 6.8.4 allows XSS. | Sep 30, 2020 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Pacsone Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.8.4 | 3 | 8.0 | 1.1% | 0 | 0 |