Vulnerabilidades en 1E
8 resultadosAnálisis Vexday
A 1E apresenta um perfil de risco moderado com 8 vulnerabilidades catalogadas, das quais 4 são críticas, mas nenhuma está sendo explorada ativamente. A fraqueza dominante é validação inadequada de entrada (CWE-20), padrão estrutural que demanda atenção em futuras atualizações. A ausência de publicações recentes sugere que o risco está estabilizado, sem emergências imediatas de segurança.
CVE-2023-45163CRITICAL1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code executionEPSS 0.9%CVE-2023-5964CRITICAL1E-Exchange-DisplayMessage instruction allows for arbitrary code executionEPSS 0.8%CVE-2023-45161CRITICAL1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code executionEPSS 0.8%CVE-2023-45160HIGHElevated Temp Directory Execution in 1E ClientEPSS 0.7%CVE-2023-45162CRITICALBlind SQL vulnerability in 1E platformEPSS 0.6%CVE-2024-7211MEDIUMThe Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.EPSS 0.2%CVE-2023-45159HIGH1E Client installer can perform arbitrary file deletion on protected filesEPSS 0.2%CVE-2025-1683HIGHSymbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File DeletionEPSS 0.2%