Communigate Pro

Vendor:

First CVE: Dec 3, 1999 · Active for 26 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.1
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Communigate Pro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 3, 1999
26 years ago
Most Recent CVE
Jan 8, 2018
3,119 days ago

CVE Severity & Scoring

Communigate Pro9 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (11.1%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None0 (0.0%)
Unknown8 (88.9%)
Required1 (11.1%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (88.9%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER length
Jan 30, 20067.533NOYES
Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inje
May 16, 20074.327NOYES
POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid ema
Dec 11, 20005.025NOYES
The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Apr 3, 20005.025NOYES
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail wi
Dec 31, 20035.824NOYES
The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack tha
Jan 8, 20185.720NONO
Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.
May 2, 20055.015NONO
Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent direct
Dec 31, 20025.015NONO
Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.
Dec 3, 19995.015NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
55.6% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Communigate Pro

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.215.70.9%00
5.0c717.510.5%01
5.0c617.510.5%01
5.0c517.510.5%01
5.0c417.510.5%01
5.0c317.510.5%01
5.0c217.510.5%01
5.0c117.510.5%01
5.0.617.510.5%01
5.0.517.510.5%01
5.0.417.510.5%01
5.0.317.510.5%01
5.0.217.510.5%01
5.0.117.510.5%01
5.017.510.5%01
4.3c215.02.5%00
4.3c115.02.5%00
4.0_b315.81.8%01
4.0_b215.81.8%01
4.0.615.81.8%01