Trms develops digital signage and media-distribution software, notably the Carousel and Seneca product lines, where vulnerabilities cluster around access-control and input-handling issues including path traversal, improper privilege management, server-side request forgery, hard-coded credentials, and unrestricted file uploads. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13020CRITICAL The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a | Aug 26, 2019 | 10.0 | 29 | NO | NO |
CVE-2018-18931HIGH An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Services directory, an attacker who ha | Oct 29, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-18930HIGH The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gai | Oct 29, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-18929HIGH The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user a | Oct 29, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-14573MEDIUM A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage before 7.3.5. The RenderingFetch API allows for the downloadi | Jul 23, 2018 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trms.
Media articles that mention a CVE ID that affects a product developed by Trms — matched by CVE ID, not by vendor name.