Scalefusion develops mobile device management and endpoint control solutions, with its vulnerability profile centered on access control and user management weaknesses within its core platform. These weakness classes reflect the authentication and authorization demands inherent to identity-centric management software; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scalefusion over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51749HIGH ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NOTE: the vendor's position is "Not vulnerable if the default | Jan 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-51748HIGH ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by preventing the launching of the file expl | Jan 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-50159HIGH In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing | Jan 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-51751MEDIUM ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Age | Jan 11, 2024 | 6.8 | 20 | NO | NO |
CVE-2023-51750MEDIUM ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows dev | Jan 11, 2024 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scalefusion.
Media articles that mention a CVE ID that affects a product developed by Scalefusion — matched by CVE ID, not by vendor name.