XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
📦
xlpd
Vendor: netsarang
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
1
Remote Access
Total CVEs
5
Total Indexed
Avg. EPSS
1.90%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.8
CVSS
Severity: HIGH
6.5
CVSS
CVE-2022-27965
RCE
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
Severity: MEDIUM
5.0
CVSS
CVE-2012-1009
Exploit Found
NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.
Severity: MEDIUM
5.0
CVSS
NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.
Severity: MEDIUM