📦 Enterprise Security Manager

by Trellix

🔍 What is Enterprise Security Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-11482

CRITICAL CVSS 9.8 Nov 29, 2024

This critical vulnerability in ESM 11.6.10 allows unauthenticated attackers to access the internal Snowservice API and execute arbitrary commands as root through command injection. Any organization ru...

CVE-2024-11481

HIGH CVSS 8.2 Nov 29, 2024

This vulnerability in ESM 11.6.10 allows unauthenticated attackers to access internal Snowservice API endpoints via path traversal. This can lead to unauthorized data access, system manipulation, and ...

CVE-2023-6071

HIGH CVSS 8.4 Nov 30, 2023

This vulnerability allows remote administrators to execute arbitrary code with root privileges on ESM systems by exploiting improper input sanitization when adding new data sources. Affected systems a...

CVE-2023-3314

HIGH CVSS 8.1 Jul 3, 2023

This vulnerability allows attackers to execute arbitrary commands on systems by exploiting improper sanitization of zip file processing. An authorized user can gain control of the zip application to r...

CVE-2023-3313

HIGH CVSS 7.8 Jul 3, 2023

This vulnerability allows unauthorized users to execute arbitrary system commands through improper input sanitization in the ESM certificate API. Attackers could escalate privileges or run malicious c...