Pass Symantec pcAnywhere awhost32 Remote Code Execution CVE-2011-3478 22 Feb 2012 10 (v2) Critical Pass Firewall Detection (2) (deprecated) 26 Oct 2007 None Pass PHP 5.6.x < 5.6.35 Security Bypass Vulnerability CVE-2018-10545 04 Mar 2019 4.7 (v3) Medium Pass Pulse Policy Secure < 9.1R8.2 (SA44588) CVE-2020-8238 CVE-2020-8243 CVE-2020-8256 09 Oct 2020 7.2 (v3) High Pass Selligent Message Studio Struts Code Execution (CVE-2017-5638) CVE-2017-5638 20 Oct 2020 10 (v3) Critical Pass Pulse Connect Secure < 9.1R9 (SA44601) CVE-2015-9251 CVE-2019-11358 CVE-2020-8255 CVE-2020-8260 CVE-2020-8261 CVE-2020-8262 CVE-2020-8263 CVE-2020-15352 30 Oct 2020 7.2 (v3) High Pass Oracle WebLogic Server RCE (CVE-2020-14882) CVE-2020-14750 CVE-2020-14882 06 Nov 2020 9.8 (v3) Critical Pass SolarWinds Orion Platform < 2019.4 HF6 / 2020.2 < 2020.2.1 HF2 Authentication Bypass (SUPERNOVA) CVE-2020-10148 28 Dec 2020 9.8 (v3) Critical Pass SAP BusinessObjects Business Intelligence Platform SSRF Vulnerability (direct check) CVE-2020-6308 08 Feb 2021 5.3 (v3) Medium Pass SSH Weak Key Exchange Algorithms Enabled 13 Oct 2021 3.7 (v3) Low Pass SSH Host Keys < 2048 Bits Considered Weak 13 Oct 2021 3.7 (v3) Low Pass Cisco IOS XE Software Smart Install Remote Code Execution Vulnerability CVE-2018-0171 29 Mar 2018 9.8 (v3) Critical Pass Comelit Intercom Master Detection 21 Apr 2017 None Pass VMware vRealize Operations Manager Web UI Detection 26 May 2016 None Pass Trend Micro OfficeScan Multiple Vulnerabilities (000263632) CVE-2020-24557 CVE-2020-24558 29 Apr 2021 7.8 (v3) High Pass Trend Micro Apex One Multiple Vulnerabilities (000263632) CVE-2020-24556 CVE-2020-24557 CVE-2020-24558 CVE-2020-24562 30 Apr 2021 7.8 (v3) High Pass Advantech WebAccess < 8.0.2015.08.16 Unspecified DLL String Handling Arbitrary Code Execution CVE-2014-9202 17 Nov 2015 6.9 (v2) Medium Pass HPE Intelligent Management Center dbman Command 10001 Information Disclosure CVE-2019-5392 10 Oct 2018 5.3 (v3) Medium Pass Kibana ESA-2019-01, ESA-2019-02, ESA-2019-03 CVE-2019-7608 CVE-2019-7609 CVE-2019-7610 04 Mar 2019 10 (v3) Critical Pass HP Universal Configuration Management Database Server Detection 18 Mar 2015 None Pass Siemens SIMATIC Logon Detection 10 Mar 2017 None Pass RuggedCom RuggedOS Known Hardcoded SSL RSA Private Key CVE-2012-4698 16 Oct 2012 4.3 (v2) Medium Pass Websense TRITON Detection 21 May 2015 None Pass Advantech / BroadWin WebAccess webvrpcs.exe Service Remote Code Execution (uncredentialed check) (deprCVE-2011-4041ecated) 02 Dec 2011 10 (v2) Critical Pass IBM iSeries Server Detection 06 Feb 2012 None Pass Magento Detection 11 May 2015 None Pass EtherNet/IP CIP List of Active Object Classes 14 May 2015 None Pass EtherNet/IP CIP Device Identification 14 May 2015 None Pass Inductive Automation Ignition Detection 02 Jun 2015 None Pass MS12-020: Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387) (uncredentialed check)CVE-2012-0002 CVE-2012-0152 22 Mar 2012 9.3 (v2) High Pass MS08-067: Vulnerability in Server Service Could Allow Remote Code Execution (958644) (ECLIPSEDWING) (uncrCVE-2008-4250edentialed check / IPS) 21 Nov 2008 9.8 (v3) Critical Pass LDAP Server NULL Bind Connection Information Disclosure 13 Aug 2001 5.3 (v3) Medium Pass 3S CoDeSys Runtime Toolkit NULL Pointer Dereference (uncredentialed check) CVE-2014-0757 18 Feb 2014 5 (v2) Medium Pass Ubiquiti airCam Detection 19 Feb 2014 None Pass McAfee Web Gateway User Interface Detection 21 Feb 2014 None Pass A10 Networks Advanced Core OS Device Detection 03 Apr 2014 None Pass RuggedCom RuggedOS SNMP Protocol Unspecified DoS CVE-2014-1966 15 Apr 2014 7.8 (v2) High Pass Exim deliver_message() Function Remote Command Execution Vulnerability (Remote) CVE-2019-10149 29 Jul 2019 9.8 (v3) Critical Pass Microsoft RDP RCE (CVE-2019-0708) (BlueKeep) (uncredentialed check) CVE-2019-0708 22 May 2019 9.8 (v3) Critical Pass GPON ONT Home Gateway Router Detection 19 Dec 2018 None Pass Citrix ADC and Citrix NetScaler Gateway Arbitrary Code Execution (CTX267027) (Direct Check) CVE-2019-19781 09 Jan 2020 9.8 (v3) Critical Pass Microsoft Remote Desktop Gateway Multiple RCE Vulnerabilities (uncredentialed check) CVE-2020-0609 CVE-2020-0610 CVE-2020-0612 29 Jan 2020 9.8 (v3) Critical Pass Tenable Nessus < 8.3.0 Multiple Vulnerabilities (TNS-2019-02) CVE-2016-4055 CVE-2017-18214 CVE-2019-1559 28 Mar 2019 5.9 (v3) Medium Pass F5 Networks BIG-IP : TMUI RCE (CVE-2020-5902) (Direct Check) CVE-2020-5902 06 Jul 2020 9.8 (v3) Critical Pass Tenable Nessus < 7.1.0 Multiple Vulnerabilities (TNS-2018-05) CVE-2018-1147 CVE-2018-1148 24 May 2018 6.5 (v3) Medium Pass EMC AutoStart ftAgent Version Detection 02 Aug 2012 None Pass JoomGallery for Joomla! < 3.3.4 SQL Injection 02 Jan 2018 6.6 (v3) Medium Pass CoDeSys Gateway Service Detection 11 Mar 2013 None Pass CA ARCserve Backup Remote Code Execution (CA20121018) (uncredentialed check) CVE-2012-2971 04 Dec 2012 10 (v3) Critical Pass VMware Workspace One Access / VMware Identity Manager Command Injection Vulnerability (VMSA-2020-0027)CVE-2020-4006 08 Dec 2020 9.1 (v3) Critical Pass Novell Privileged User Manager Daemon Detection 02 Sep 2009 None Pass EMC Replication Manager irccd.exe RunProgram Message Handling Arbitrary Command Execution 02 Sep 2009 10 (v2) Critical Pass EMC Replication Manager Client Detection 02 Sep 2009 None Pass EMC Replication Manager Server Detection 02 Sep 2009 None Pass Cisco ASA 5500 Series Adaptive Security Appliance NTLMv1 Authentication Bypass (cisco-sa-20100217-asa)CVE-2010-0568 01 Mar 2010 7.8 (v2) High Pass Wyse Device Manager HAgent Service Detection 02 Sep 2009 None Pass Web Application Firewall Detection 10 Dec 2009 None Pass Mac OS X AFP Shared Folders Unauthenticated Access (Security Update 2010-006) (uncredentialed check)CVE-2010-1820 21 Sep 2010 7.5 (v2) High Pass Cisco Secure Access Control Server Detection 19 Aug 2008 None Pass Atlassian JIRA Detection 20 Apr 2010 None Pass PHP 5.6.x < 5.6.33 Multiple Vulnerabilities CVE-2018-5711 CVE-2018-5712 12 Jan 2018 6.1 (v3) Medium Pass PHP 7.0.x < 7.0.27 Multiple Vulnerabilities CVE-2018-5711 CVE-2018-5712 CVE-2018-14884 12 Jan 2018 6.1 (v3) Medium Pass PHP 7.1.x < 7.1.13 Multiple Vulnerabilities CVE-2018-5711 CVE-2018-5712 CVE-2018-14884 12 Jan 2018 6.1 (v3) Medium Pass Atlassian JIRA Plugins Detection 23 Sep 2019 None Pass PHP 7.2.x < 7.2.1 Multiple Vulnerabilities CVE-2018-5711 CVE-2018-5712 CVE-2018-14884 12 Jan 2018 6.1 (v3) Medium Pass Oracle Primavera Unifier Platform Component Unspecified Remote Issue (January 2018 CPU) CVE-2018-2620 19 Jan 2018 8.1 (v3) High Pass VMware vCenter Server 6.5 / 6.7 / 7.0 Information Disclosure (VMSA-2022-0009) CVE-2022-22948 29 Mar 2022 6.5 (v3) Medium Pass SSH Multiple Device Default Credentials 30 Jan 2018 9.8 (v3) Critical Pass Default Password 'St0r@ge!' for 'administrator' Account 08 Mar 2018 9.8 (v3) Critical Pass PHP 5.6.x < 5.6.34 Stack Buffer Overflow CVE-2018-7584 08 Mar 2018 9.8 (v3) Critical Pass PHP 7.0.x < 7.0.28 Stack Buffer Overflow CVE-2018-7584 08 Mar 2018 9.8 (v3) Critical Pass PHP 7.1.x < 7.1.15 Stack Buffer Overflow CVE-2018-7584 08 Mar 2018 9.8 (v3) Critical Pass ManageEngine EventLog Analyzer XSS Vulnerability CVE-2018-8721 24 Mar 2018 6.1 (v3) Medium Pass MikroTik RouterOS < 6.40.7 or 6.41.x < 6.41.3 SMB Buffer Overflow CVE-2018-7445 22 Mar 2018 9.8 (v3) Critical Pass SSH Multiple Device Default Credentials (PCI) 03 Apr 2018 9.8 (v3) Critical Pass PHP 7.2.x < 7.2.3 Stack Buffer Overflow CVE-2018-7584 08 Mar 2018 9.8 (v3) Critical Pass nginx < 0.7.66 / 0.8.x < 0.8.40 Information Disclosure CVE-2010-2263 09 Mar 2018 5.3 (v3) Medium Pass nginx < 0.7.67 / 0.8.x < 0.8.41 DoS CVE-2010-2266 09 Mar 2018 5.3 (v3) Medium Pass Oracle Primavera P6 Enterprise Project Portfolio Management (EPPM) Multiple Vulnerabilities (April 2018 CPU)CVE-2018-2849 19 Apr 2018 7.7 (v3) High Pass Dell iDRAC Products Multiple Vulnerabilities (Mar 2018) CVE-2018-1207 CVE-2018-1211 CVE-2018-1000116 20 Apr 2018 9.8 (v3) Critical Pass Schneider Electric InduSoft Web Studio / InTouch Machine Edition Opcode 50 mbstowcs() Stack OverflowCVE-2018-8840 23 Apr 2018 9.8 (v3) Critical Pass CKEditor 4.5.11 < 4.9.2 Enhanced Image Plugin XSS CVE-2018-9861 27 Apr 2018 6.1 (v3) Medium Pass Oracle WebLogic Server Deserialization RCE (CVE-2018-2628) CVE-2018-2628 30 Apr 2018 9.8 (v3) Critical Pass Jenkins < 2.107.2 / 2.116 Multiple Vulnerabilities CVE-2018-1000169 CVE-2018-1000170 03 May 2018 5.3 (v3) Medium Pass PHP 5.6.x < 5.6.36 Multiple Vulnerabilities CVE-2018-10546 CVE-2018-10547 CVE-2018-10548 CVE-2018-10549 04 May 2018 8.8 (v3) High Pass PHP 7.0.x < 7.0.30 Multiple Vulnerabilities CVE-2018-10545 CVE-2018-10546 CVE-2018-10547 CVE-2018-10548 CVE-2018-10549 04 May 2018 8.8 (v3) High Pass PHP 7.1.x < 7.1.17 Multiple Vulnerabilities CVE-2018-10545 CVE-2018-10546 CVE-2018-10547 CVE-2018-10548 CVE-2018-10549 04 May 2018 8.8 (v3) High Pass HP Service Manager 9.30.x / 9.31.x / 9.32.x / 9.33.x / 9.34.x / 9.35.x < 9.35.6007 / 9.40.x / 9.41.x < 9.41.6000 / 9.50.x / 9.51.x Remote SQL InjectionCVE-2018-6494 18 May 2018 5.4 (v3) Medium Pass PHP 7.1.x < 7.1.5 Multiple Vulnerabilities CVE-2017-8923 CVE-2017-9119 25 May 2017 9.8 (v3) Critical Pass HP OfficeJet Pro and PageWide Pro PJL Interface Directory Traversal RCE CVE-2017-2741 26 May 2017 9.8 (v3) Critical Pass Mount iSCSI Targets with 'None' Authentication 31 May 2017 5.3 (v3) Medium Pass Oracle Primavera Unifier (Jan 2022 CPU) CVE-2020-8908 CVE-2021-2351 CVE-2021-29425 CVE-2021-37714 CVE-2021-38153 CVE-2021-42575 CVE-2021-44832 19 Jan 2022 9.8 (v3) Critical Pass Oracle GoldenGate Manager < 12.2.0.1.1 OBEY Command ggserr.log File Handling RCE 05 Jun 2017 9.8 (v3) Critical Pass PHP 5.6.x < 5.6.39 Multiple vulnerabilities CVE-2018-19518 CVE-2018-19935 CVE-2018-20783 19 Dec 2018 7.5 (v3) High Pass Advantech WebAccess Authentication Bypass CVE-2017-5152 30 Jan 2017 9.1 (v3) Critical Pass NUUO NVR Web Interface Detection 18 Oct 2017 None Pass AVTech Web Interface Detection 23 Oct 2017 None Pass Microsoft Windows Search Remote Code Execution Vulnerability (CVE-2017-8543) CVE-2017-8543 22 Aug 2017 9.8 (v3) Critical Pass Advantech WebAccess webvprcs IOCTL 70603 Stack Overflow CVE-2019-3975 24 Sep 2019 9.8 (v3) Critical Pass FreeBSD TCP/IP Stack - HTTP Detection 17 May 2021 None Pass Pivotal RabbitMQ Management Plugin Detection 19 May 2017 None Pass Belkin Web Interface Detection 10 Jul 2017 None Pass GPON ONT Home Gateway Authenticated Remote Command Execution (CVE-2019-3919) CVE-2019-3919 25 Mar 2019 8.8 (v3) High Pass SonicWall Secure Remote Access (SRA) Pre-Authentication SQLi (CVE-2019-7481) CVE-2019-7481 11 Jun 2021 7.5 (v3) High Pass Johnson Controls exacqVision Web Service Detection 30 Jun 2021 None Pass Johnson Controls exacqVision Web Service Information Disclosure (JCI-PSA-2021-03) CVE-2021-27656 30 Jun 2021 7.5 (v3) High Pass Serendipity < 2.1.1 Multiple Vulnerabilities CVE-2016-9681 CVE-2016-10082 CVE-2017-5474 CVE-2017-5475 CVE-2017-5476 14 Jun 2017 9.8 (v3) Critical Pass PHP 7.0.x < 7.0.20 Multiple Vulnerabilities 15 Jun 2017 9.8 (v3) Critical Pass PHP 7.1.x < 7.1.6 Multiple Vulnerabilities 15 Jun 2017 9.8 (v3) Critical Pass Veritas NetBackup Appliance 2.7.x / 3.0.x Remote Command Execution (VTS17-005) (exploit) CVE-2017-8859 22 May 2017 9.8 (v3) Critical Pass DNN (DotNetNuke) 3.0.0 < 9.1.0 SWF File Handling XSS 12 Jul 2017 4.7 (v3) Medium Pass Apache 2.4.x < 2.4.27 Multiple Vulnerabilities CVE-2017-9788 CVE-2017-9789 18 Jul 2017 9.1 (v3) Critical 44
RELAYTO Penetration Test Results Page 43 Page 45