Securepoint GmbH develops security appliances and VPN client software, with a focused vulnerability profile centered on its OpenVPN client and unified threat management platforms. The reported exposure reflects access-control and resource-handling issues such as improper privilege management, incorrect authorization, and use of uninitialized resources that recur across these products; live severity, exploitation, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Securepoint GmbH over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22620HIGH An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. Thi | Apr 12, 2023 | 7.5 | 36 | NO | YES |
CVE-2023-22897MEDIUM An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticate | Apr 12, 2023 | 6.5 | 34 | NO | YES |
CVE-2021-35523HIGH Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user | Jun 28, 2021 | 7.8 | 25 | NO | NO |
CVE-2023-47101HIGH The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair. | Oct 30, 2023 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Securepoint GmbH.
Media articles that mention a CVE ID that affects a product developed by Securepoint GmbH — matched by CVE ID, not by vendor name.