Nec Expresscluster X vulnerabilities
19 known vulnerabilities affecting nec/expresscluster_x.
Total CVEs
19
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH10
Vulnerabilities
Page 1 of 1
CVE-2023-39547HIGHCVSS 8.8v1.0v2.0+10 more2023-11-17
CVE-2023-39547 [HIGH] CWE-294 CVE-2023-39547: CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
nvd
CVE-2023-39546HIGHCVSS 8.8v1.0v2.0+11 more2023-11-17
CVE-2023-39546 [HIGH] CWE-836 CVE-2023-39546: CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
nvd
CVE-2023-39545HIGHCVSS 8.8v1.0v2.0+11 more2023-11-17
CVE-2023-39545 [HIGH] CWE-552 CVE-2023-39545: CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
nvd
CVE-2023-39548HIGHCVSS 8.8v1.0v2.0+11 more2023-11-17
CVE-2023-39548 [HIGH] CWE-434 CVE-2023-39548: CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
nvd
CVE-2023-39544HIGHCVSS 8.8v1.0v2.0+11 more2023-11-17
CVE-2023-39544 [HIGH] CWE-862 CVE-2023-39544: CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
nvd
CVE-2022-34823CRITICALCVSS 9.8≤ 5.02022-11-08
CVE-2022-34823 [CRITICAL] CWE-120 CVE-2022-34823: Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially e
nvd
CVE-2022-34822CRITICALCVSS 9.8≤ 5.02022-11-08
CVE-2022-34822 [CRITICAL] CWE-22 CVE-2022-34822: Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for W
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially ex
nvd
CVE-2022-34824CRITICALCVSS 9.8≤ 5.02022-11-08
CVE-2022-34824 [CRITICAL] CWE-276 CVE-2022-34824: Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSC
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system an
nvd
CVE-2022-34825CRITICALCVSS 9.8≤ 5.02022-11-08
CVE-2022-34825 [CRITICAL] CWE-427 CVE-2022-34825: Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 f
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potential
nvd
CVE-2021-20704CRITICALCVSS 9.8≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20704 [CRITICAL] CWE-120 CVE-2021-20704: Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Wind
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
nvd
CVE-2021-20702CRITICALCVSS 9.8≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20702 [CRITICAL] CWE-120 CVE-2021-20702: Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EX
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
nvd
CVE-2021-20703CRITICALCVSS 9.8≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20703 [CRITICAL] CWE-120 CVE-2021-20703: Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EX
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
nvd
CVE-2021-20700CRITICALCVSS 9.8≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20700 [CRITICAL] CWE-120 CVE-2021-20700: Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLU
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
nvd
CVE-2021-20701CRITICALCVSS 9.8≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20701 [CRITICAL] CWE-120 CVE-2021-20701: Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLU
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
nvd
CVE-2021-20705HIGHCVSS 7.5≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20705 [HIGH] CWE-20 CVE-2021-20705: Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier,
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.
nvd
CVE-2021-20707HIGHCVSS 7.5≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20707 [HIGH] CWE-20 CVE-2021-20707: Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and e
Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network..
nvd
CVE-2021-20706HIGHCVSS 7.5≥ 1.0, ≤ 4.32021-11-03
CVE-2021-20706 [HIGH] CWE-20 CVE-2021-20706: Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier,
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.
nvd
CVE-2020-17408HIGHCVSS 7.5v4.1v4.22020-09-10
CVE-2020-17408 [HIGH] CWE-611 CVE-2020-17408: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document sp
nvd
CVE-2016-1145HIGHCVSS 7.5v3.32016-01-30
CVE-2016-1145 [HIGH] CWE-22 CVE-2016-1145: Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows
Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors.
nvd