← Back

Castlerock

castlerock

8 CVEs • 3 products

Products (3)

Click to collapse
Toggle

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Castlerock
1Snmpc Online
Nov 21, 2024
Apr 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
1Castlerock
1Snmpc Online
Nov 21, 2024
Apr 9, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.
1Castlerock
1Snmpc Online
Nov 21, 2024
Apr 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.
1Castlerock
1Snmpc Online
Nov 21, 2024
Apr 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.
1Castlerock
1Snmpc Online
Nov 21, 2024
Apr 9, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
1Castlerock
1Simple Network Management Protocol Console
Nov 21, 2024
Jul 12, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.
1Castlerock
1Snmpc
May 13, 2026
Apr 10, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
1Castlerock
1Snmpc
May 13, 2026
Apr 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.