Inspector
Vendor:
First CVE: Oct 9, 2019 · Active for 6 years
11
Total CVEs
More Total CVEs than 89% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Inspector over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 9, 2019
6 years ago
Most Recent CVE
Oct 9, 2019
2,480 days ago
CVE Severity & Scoring
Inspector11 CVEs
9%
64%
27%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1584CRITICAL A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbo | Oct 9, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-15020CRITICAL A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspecto | Oct 9, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-15019CRITICAL A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspecto | Oct 9, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-15014HIGH A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execute arbitrary system commands in the CLI. | Oct 9, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-15016HIGH An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated use | Oct 9, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-15017HIGH The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker t | Oct 9, 2019 | 8.4 | 25 | NO | NO |
CVE-2019-15015HIGH In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorize | Oct 9, 2019 | 8.4 | 25 | NO | NO |
CVE-2019-15022HIGH A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing. | Oct 9, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-15018HIGH A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different custome | Oct 9, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-15023HIGH A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being stored in cleartext in device configurat | Oct 9, 2019 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Inspector
Top CWEs
Versions
No cataloged versions.