CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
The Automox Agent before 40 on Windows incorrectly sets permissions on key files. | 7.8 |
High |
||
Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process. | 7 |
High |
||
Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process. | 5.5 |
Medium |
||
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory. | 7.8 |
High |
||
Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent. | 5.3 |
Medium |
||
Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent. | 3.3 |
Low |