Syscomgo's vulnerability footprint centers on its omFlow product, a narrowly scoped offering that exhibits recurring exposure through information-disclosure and path-traversal weaknesses, alongside access-control issues that are characteristic of web application and file-handling logic. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syscomgo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8779HIGH OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system | Sep 16, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-8777HIGH OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is ena | Sep 16, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-8780MEDIUM OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and pa | Sep 16, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-8778MEDIUM OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files. | Sep 16, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syscomgo.
Media articles that mention a CVE ID that affects a product developed by Syscomgo — matched by CVE ID, not by vendor name.