📦

incapptic_connect

Vendor: ivanti

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 11.73% Exploit Prob.
Latest CVE CVE-2022-22572 Apr 11

Security Vulnerability Index

Page 1 / 1
8.8 CVSS

A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.

EPSS: 19.73%
4.8 CVSS

An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions.

EPSS: 0.09%
7.2 CVSS

A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.

EPSS: 15.38%