Win911 develops on-premises alerting and mobile notification software that connects to industrial control systems and enterprise monitoring platforms, with exposure centered on its core Win-911 and Mobile-911 Server products. The recurring vulnerability signal reflects improper default permission configurations in these applications, a structural issue that can expose alert data and administrative functions to unintended access. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Win911 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13541HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install directory. Depending on the vector chosen, an att | Jan 5, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-23922HIGH WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the Program Announcer directory and elevate permissions | Feb 24, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-23104HIGH WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the program Operator Workspace directory, which holds D | Feb 24, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-13539HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via “WIN-911 Mobile Runtime” servi | Jan 5, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-13540HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via WIN-911 Account Change Utility | Jan 5, 2021 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Win911.
Media articles that mention a CVE ID that affects a product developed by Win911 — matched by CVE ID, not by vendor name.