CVE-2019-14480
CRITICALAdRem NetCrunch 10.6.0.4587 - Auth Bypass
Title source: llmDescription
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
Scores
CVSS v3
9.8
EPSS
0.0029
EPSS Percentile
52.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-311
CWE-200
CWE-522
CWE-338
CWE-732
Status
published
Affected Products (1)
adremsoft/netcrunch
< 11.0.0.5282
Timeline
Published
Dec 16, 2020
Tracked Since
Feb 18, 2026