Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Deception HIGH 8.8
CVE-2022-24388

Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deceptio…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24389

Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and De…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24390

Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network …

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24391

Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24392

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_tes…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24393

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 8.8
CVE-2022-24394

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkf…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 7.8
CVE-2022-0486

Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with loc…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 7.8
CVE-2022-0997

Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, admin…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception CRITICAL 9.8
CVE-2021-35048

Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could l…

Fix: 9.3.7+
Fix from $2,300 2021-06-25
Deception HIGH 8.8
CVE-2021-35047

Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the…

Fix: 9.3.7+
Fix from $1,950 2021-06-25
Deception HIGH 8.8
CVE-2021-35049

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could…

Fix: 9.3.7+
Fix from $1,950 2021-06-25
Deception HIGH 7.5
CVE-2021-35050

User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the C…

Fix: 9.3.3+
Fix from $1,950 2021-06-25