Known vulnerabilities in Kerio Control
Vendor:
GFI Software
Software:
Kerio Control
Software CPE:
cpe:2.3:a:gfi:kerio_control:*:*:*:*:*:*:*:*
Website:
https://www.gfi.com/
Total vulnerabilities:
4
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.9
Breakdown by Severity Chart
9.6.1p1
9.6.1
9.6.0
10.0.0
9.5.0 Patch 3
9.5.0 Patch 2
9.5.0 Patch 1
9.5.0
9.5p1
9.4.5 Patch 2
9.4.5 Patch 1
9.4.5
9.4.4p1
9.4.4
9.4.3 Patch 4
9.4.3 Patch 3
9.4.3 Patch 2
9.4.3 Patch 1
9.4.3
9.4.2 Patch 1
9.4.2
9.3.6.1
9.3.5
9.3.4
9.3.3
9.3.2
8.3.2
8.3.1
8.3
8.0
9.2
9.2.1
9.3.1
9.3
9.2.9
9.2.8
9.2.7
9.2.6
9.2.5
9.2.4
9.2.3
9.2.2
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU101812 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2024-52875 |
CWE-113 | Medium | - | 17.12.2024 |
SB2024121731 |
||
| #VU21403 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2014-3857 |
CWE-89 | Medium | 8.3.2 | 29.09.2019 |
SB2014070301 |
||
| #VU21402 - Permissions, Privileges, and Access Controls |
CWE-264 | Medium | 9.3.1 | 29.09.2019 |
SB2019092903 |
||
| #VU21401 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-16414 |
CWE-79 | Low | 9.3.1 | 29.09.2019 |
SB2019092903 |