← Back

Veraport G3

veraport_g3

Vendor: Wizvera • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wizvera
1Veraport G3
Nov 21, 2024
Dec 20, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to malicious file. A remote unauthenticated attacker may use this vulnerability to execute arbitrary file.
1Wizvera
1Veraport G3
Nov 21, 2024
Dec 20, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary file download and execution. This results in remote code execution.