Vasco develops authentication and credential-management solutions centered on its Digipass hardware tokens and IdentiKey authentication server, positioning these products as foundational components in enterprise identity infrastructure. The vulnerability signals observed in this vendor cluster around authentication-bypass conditions and input-handling weaknesses in web interfaces, reflecting the security-sensitive nature of authentication platforms and the attack surface inherent to credential-validation flows. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vasco over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7349MEDIUM Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Citrix Web Interface allows remote attackers to inject arbitra | Sep 28, 2017 | 6.1 | 17 | NO | NO |
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, in | Jan 13, 2014 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vasco.
Media articles that mention a CVE ID that affects a product developed by Vasco — matched by CVE ID, not by vendor name.