Secureanywhere
Vendor:
First CVE: Sep 12, 2018 · Active for 7 years
6
Total CVEs
More Total CVEs than 83% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secureanywhere over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 12, 2018
7 years ago
Most Recent CVE
May 12, 2023
1,172 days ago
CVE Severity & Scoring
Secureanywhere6 CVEs
83%
17%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16962HIGH Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges. | Sep 12, 2018 | 7.8 | 25 | NO | NO |
CVE-2023-29820MEDIUM An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the | May 12, 2023 | 5.5 | 22 | NO | NO |
CVE-2023-29819MEDIUM An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. | May 12, 2023 | 5.5 | 22 | NO | NO |
CVE-2023-29818MEDIUM An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being st | May 12, 2023 | 5.5 | 21 | NO | NO |
CVE-2021-40425MEDIUM An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An | Apr 14, 2022 | 6.5 | 17 | NO | NO |
CVE-2021-40424MEDIUM An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An | Apr 14, 2022 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Secureanywhere
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 21.4 | 2 | 6.5 | 0.3% | 0 | 0 |