Telos maintains a specialized automated message handling system, a narrowly scoped product that sits in enterprise communication and workflow environments despite its modest overall vulnerability footprint. The recurring exposure centers on web-layer input handling and information disclosure, reflected in cross-site scripting and sensitive-data exposure vulnerabilities characteristic of systems that process and display user-controlled or privileged message content. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telos over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9539MEDIUM : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup.asp of Telos Automated Message Handling System allows a rem | Jan 3, 2020 | 6.1 | 21 | NO | NO |
CVE-2019-9540MEDIUM : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Telos Automated Message Handling System allows a remote attacke | Jan 3, 2020 | 6.1 | 20 | NO | NO |
CVE-2019-9542MEDIUM : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote at | Jan 3, 2020 | 6.1 | 17 | NO | NO |
CVE-2019-9541MEDIUM : Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This iss | Jan 3, 2020 | 6.1 | 17 | NO | NO |
CVE-2019-9538MEDIUM : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL parameter of Telos Automated Message Handling System allows a | Jan 3, 2020 | 6.1 | 17 | NO | NO |
CVE-2019-9537MEDIUM : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote at | Jan 3, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telos.
Media articles that mention a CVE ID that affects a product developed by Telos — matched by CVE ID, not by vendor name.