Starface develops a unified communications and collaboration platform, with its vulnerability disclosures centered on the core Starface client product. The recurring weakness classes—uncontrolled search path elements and insufficient password hashing—reflect common misconfigurations in path resolution and credential storage within communications software. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Starface over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33243HIGH RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext passwo | Jun 15, 2023 | 8.1 | 38 | NO | YES |
CVE-2020-10515CRITICAL STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006. | Apr 2, 2020 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Starface.
Media articles that mention a CVE ID that affects a product developed by Starface — matched by CVE ID, not by vendor name.