📦

tinycheck

Vendor: kaspersky

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 1.33% Exploit Prob.
Latest CVE CVE-2020-36200 Jan 26

Security Vulnerability Index

Page 1 / 1
6.5 CVSS

TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.

EPSS: 0.79%
9.8 CVSS

TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.

EPSS: 2.18%
9.8 CVSS

In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.

EPSS: 1.03%