Shimovpn develops a focused VPN client product with a modest but persistent vulnerability footprint centered on input handling, code integrity, and privilege-management issues endemic to network-access software. The vendor's disclosures cluster around improper input validation, unsigned or unverified code delivery, and improper privilege escalation—weakness classes that reflect the authentication, update, and access-control surface typical of VPN applications. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shimovpn over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-4005HIGH An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRoutingWithCommand function. A user with local access can use this | Apr 17, 2019 | 7.8 | 26 | NO | NO |
CVE-2018-4006HIGH An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is able to write a file anywhere | Apr 17, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-4009HIGH An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerabi | Apr 15, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-4008HIGH An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a user-supplied script argument and | Apr 15, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-4007HIGH An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected file | Apr 17, 2019 | 7.1 | 22 | NO | NO |
CVE-2018-4004MEDIUM An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root user is able to kill any privile | Apr 17, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shimovpn.
Media articles that mention a CVE ID that affects a product developed by Shimovpn — matched by CVE ID, not by vendor name.