Setelsa Security's vulnerability footprint is concentrated in a narrowly scoped product line centered on its Conacwin application. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Setelsa Security over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25068HIGH Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server vi | Sep 3, 2020 | 7.5 | 24 | NO | NO |
CVE-2023-3512HIGH Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an attacker to perform an arbitra | Oct 4, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-4037MEDIUM Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by s | Oct 4, 2023 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Setelsa Security.
Media articles that mention a CVE ID that affects a product developed by Setelsa Security — matched by CVE ID, not by vendor name.