Zingbox develops the Inspector platform, a network assessment and device-visibility tool deployed in healthcare and critical infrastructure environments where comprehensive endpoint and IoT asset discovery is essential. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes centered on authentication and credential handling—including hard-coded credentials, authentication bypass via spoofing, and cleartext storage—alongside input-validation and command-injection flaws that reflect the product's role parsing and managing untrusted device communications. Defenders should prioritize patching this vendor's releases given the critical nature of disclosed flaws and the sensitive nature of networks where Inspector operates; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zingbox over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1584CRITICAL A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbo | Oct 9, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-15020CRITICAL A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspecto | Oct 9, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-15019CRITICAL A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspecto | Oct 9, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-15014HIGH A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execute arbitrary system commands in the CLI. | Oct 9, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-15016HIGH An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated use | Oct 9, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-15017HIGH The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker t | Oct 9, 2019 | 8.4 | 25 | NO | NO |
CVE-2019-15015HIGH In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorize | Oct 9, 2019 | 8.4 | 25 | NO | NO |
CVE-2019-15022HIGH A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing. | Oct 9, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-15018HIGH A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different custome | Oct 9, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-15023HIGH A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being stored in cleartext in device configurat | Oct 9, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zingbox.
Media articles that mention a CVE ID that affects a product developed by Zingbox — matched by CVE ID, not by vendor name.