Pass Siemens SCALANCE S612 Firewall Detection 06 May 2015 None Pass VMware vCenter Operations Manager Web UI Detection 10 Apr 2015 None Pass Atlassian Confluence < 6.13.18 / 6.14 < 7.4.6 / 7.5 < 7.8.3 Arbitrary File Read (CONFSERVER-60469) CVE-2020-29448 26 Feb 2021 5.3 (v3) Medium Pass Citrix ADC and Citrix NetScaler Gateway Reflected Code Injection (CTX276688) (Direct Check) CVE-2020-8194 02 Mar 2021 6.5 (v3) Medium Pass Oracle Secure Global Desktop Administration Console Detection 01 Nov 2013 None Pass Oracle Portal Detection 22 Nov 2013 None Pass Tenable SecurityCenter Detection 02 Dec 2013 None Pass Web Site Hosting Malicious Binaries 21 Nov 2013 8.3 (v3) High Pass ManageEngine Desktop Central Detection 04 Dec 2013 None Pass HP AutoPass License Server Detection 27 Jun 2014 None Pass Ericom AccessNow Server Detection 30 Jun 2014 None Pass F5 Networks ARX Data Manager Web Interface Detection 01 Jul 2014 None Pass Silver Peak VX Detection 25 Sep 2014 None Pass Oracle MapViewer Detection 08 Oct 2014 None Pass Cisco Integrated Management Controller WebUI Detection 13 Oct 2014 None Pass Apache Log4Shell RCE detection via callback correlation (Direct Check POP3) CVE-2021-44228 17 Dec 2021 10 (v3) Critical Pass TIBCO Spotfire Server Detection 13 Oct 2014 None Pass Oracle Endeca Information Discovery Studio Detection 21 Oct 2014 None Pass Novell GroupWise Internet Agent Request Content-Length Header Parsing Remote Overflow CVE-2012-0271 02 Oct 2012 10 (v2) Critical Pass Clorius Controls ISC SCADA Detection 14 May 2013 None Pass JBossWS Endpoint Uses Unsafe Encryption CVE-2011-1096 23 Apr 2013 5 (v2) Medium Pass Tridium Niagara AX Web Server Detection 03 Jul 2013 None Pass Tridium Niagara AX Web Server Directory Traversal 'config.bog' Disclosure Remote Compromise CVE-2012-4701 03 Jul 2013 9.3 (v2) High Pass Clorius Controls ISC SCADA Information Disclosure 14 May 2013 5 (v2) Medium Pass HTTP Cookie 'secure' Property Transport Mismatch 10 Sep 2013 None Pass MS10-075: Vulnerability in Media Player Network Sharing Service Could Allow Remote Code Execution (2281679) (uncrCVE-2010-3225edentialed check) 18 Oct 2010 9.3 (v2) High Pass Patch Management: VMware Go Server Settings (deprecated) 06 Dec 2011 None Pass MS11-100: ASP.NET Could Allow Denial of Service (2638420) (uncredentialed check) CVE-2011-3414 16 Jan 2012 5 (v2) Medium Pass Patch Management: Missing updates from VMware Go (deprecated) 06 Dec 2011 None Pass EMC SMARTS Application Server Detection 17 Feb 2012 None Pass Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances (cisco-sa-20100217-asa) CVE-2010-0149 CVE-2010-0150 CVE-2010-0151 CVE-2010-0565 CVE-2010-0566 CVE-2010-0567 CVE-2010-0568 CVE-2010-0569 25 Feb 2010 9.4 (v2) High Pass Splunk Management API Detection 01 Sep 2010 None Pass Cisco Secure Access Control Server (ACS) CSuserCGI.exe Multiple Remote Overflows CVE-2008-0532 19 Aug 2008 10 (v2) Critical Pass Cisco Secure Access Control Server (ACS) CSUserCGI.exe Help Facility XSS CVE-2008-0533 19 Aug 2008 4.3 (v2) Medium Pass Oracle WebLogic Server Java Object Deserialization RCE (CVE-2020-2883) CVE-2020-2883 02 Jul 2020 9.8 (v3) Critical Pass Apache Tomcat 8.0.0.RC1 < 8.0.47 Multiple Vulnerabilities CVE-2017-12617 06 Oct 2017 8.1 (v3) High Pass Apache Tomcat 6.0.x < 6.0.24 Multiple Vulnerabilities CVE-2017-5647 CVE-2017-5664 CVE-2017-12615 CVE-2017-12617 02 Nov 2017 8.1 (v3) High Pass Atlassian JIRA < 8.5.11 / 8.6.x < 8.13.3 / 8.14.x < 8.15.0 Multiple XSS CVE-2020-36234 CVE-2020-36236 12 Mar 2021 6.1 (v3) Medium Pass Tenable Nessus 8.9.0 < 8.13.2 Multiple Vulnerabilities (TNS-2021-05) CVE-2021-3449 CVE-2021-3450 02 Apr 2021 7.4 (v3) High Pass Juniper Junos Local File Include Vulnerability (JSA11021) CVE-2020-1631 01 May 2020 9.8 (v3) Critical Pass Palo Alto Networks PAN-OS 8.0.x < 8.1.15 / 8.1.x < 8.1.15 / 9.0.x < 9.0.9 / 9.1.x < 9.1.3 Authentication Bypass in SAML Authentication (CVE-2020-2021)CVE-2020-2021 29 Jun 2020 10 (v3) Critical Pass Oracle E-Business Multiple Vulnerabilities (July 2016 CPU) CVE-2016-3491 CVE-2016-3512 CVE-2016-3520 CVE-2016-3522 CVE-2016-3523 CVE-2016-3524 CVE-2016-3525 CVE-2016-3528 CVE-2016-3532 CVE-2016-3533 CVE-2016-3534 CVE-2016-3535 CVE-2016-3536 CVE-2016-3541 CVE-2016-3542 CVE-2016-3543 CVE-2016-3545 CVE-2016-3546 CVE-2016-3547 CVE-2016-3548 CVE-2016-3549 CVE-2016-3558 CVE-2016-355920 Jul 2016 9.1 (v3) Critical Pass Oracle Primavera Unifier (Apr 2021 CPU) CVE-2020-11022 CVE-2020-11023 CVE-2020-13956 CVE-2020-17521 22 Apr 2021 6.1 (v3) Medium Pass Oracle E-Business Suite (Jan 2022 CPU) CVE-2019-10086 CVE-2020-6950 CVE-2022-21250 CVE-2022-21251 CVE-2022-21255 CVE-2022-21273 CVE-2022-21274 CVE-2022-21354 CVE-2022-2137320 Jan 2022 8.1 (v3) High Pass Dell iDRAC XSS (DSA-2021-073) CVE-2021-21542 23 Apr 2021 4.8 (v3) Medium Pass Dell iDRAC Multiple Vulnerabilities (DSA-2021-073) CVE-2021-21539 CVE-2021-21540 CVE-2021-21541 CVE-2021-21543 CVE-2021-21544 23 Apr 2021 8.1 (v3) High Pass Cisco Unified Communications Manager RCE (cisco-sa-cucm-rce-pqVYwyb) CVE-2021-1362 23 Apr 2021 8.8 (v3) High Pass Johnson Controls exacqVision Web Service Information Disclosure (JCI-PSA-2021-16) CVE-2021-27664 02 Nov 2021 9.8 (v3) Critical Pass PHP 7.0.x < 7.0.12 Multiple Vulnerabilities 18 Oct 2016 9.8 (v3) Critical Pass Default Password '888888' for '888888' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'password' for 'admin1' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '1111111' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '1234' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '12345' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '123456' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Apache Tomcat 8.5.55 < 8.5.75 multiple vulnerabilities CVE-2022-23181 26 Jan 2022 7 (v3) High Pass Default Password '4321' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '54321' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '7ujMko0admin' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'admin1234' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'meinsm' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'pass' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'smcadmin' for 'admin' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '1234' for 'administrator' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'meinsm' for 'Administrator' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'f****r' for 'mother' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '00000000' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '1111' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '1234' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '12345' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '123456' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '54321' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass CodeMeter Runtime Buffer Over-read (WIBU-210423-01) CVE-2021-20093 23 Jun 2021 9.1 (v3) Critical Pass Default Password '7ujMko0admin' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '7ujMko0vizxv' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password '888888' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'Zte521' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'anko' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'dreambox' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'hi3518' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'ikwb' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'juantech' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'jvbzd' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass ManageEngine ADAudit Plus < Build 7006 File Upload RCE CVE-2021-42847 29 Nov 2021 9.8 (v3) Critical Pass Default Password 'klv1234' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'pass' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'realtek' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'system' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass HP PageWide Printer Web Interface Detection 06 Dec 2021 None Pass Modicon Quantum HTTP Server 'formTest' 'name' Parameter XSS CVE-2018-7810 26 Nov 2018 6.1 (v3) Medium Pass TP-Link Unauthenticated CGI Cross-Site Request Forgery (Remote) CVE-2018-11714 CVE-2018-15702 01 Oct 2018 9.8 (v3) Critical Pass Default Password 'user' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'vizxv' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass SQLi scanner 04 Mar 2019 8.3 (v3) High Pass Default Password 'xmhdipc' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass NetApp OnTAP Web Detection 06 Jun 2018 None Pass Default Password 'zlxx.' for 'root' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'service' for 'service' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'tech' for 'tech' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Default Password 'ubnt' for 'ubnt' Account CVE-1999-0502 28 Oct 2016 9.8 (v3) Critical Pass Hikvision IP Camera Web Interface Detection 28 Feb 2018 None Pass Trend Micro Smart Protection Server Detection 08 Mar 2018 None Pass Oracle WebLogic Server Java Object Deserialization RCE (October 2016 CPU) CVE-2016-5535 03 Nov 2016 9.8 (v3) Critical Pass JBoss Enterprise Application Platform doFilter() Method Insecure Deserialization RCE CVE-2017-12149 24 Apr 2018 9.8 (v3) Critical Pass Western Digital TV Web Interface Detection 08 Sep 2017 None Pass Open Network Video Interface Forum (ONVIF) Protocol Detection 17 Oct 2017 None Pass Pulse Policy Secure Detection 08 Sep 2017 None Pass Brother Printer Debut Embedded HTTP Server Detection 30 Nov 2017 None Pass HP System Management Homepage < 7.6 Multiple Vulnerabilities (HPSBMU03653) (httpoxy) CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2109 CVE-2016-3739 CVE-2016-4070 CVE-2016-4071 CVE-2016-4072 CVE-2016-4342 CVE-2016-4343 CVE-2016-4393 CVE-2016-4394 CVE-2016-4395 CVE-2016-4396 CVE-2016-4537 CVE-2016-4538 CVE-2016-4539 CVE-2016-4540 CVE-2016-4541 CVE-2016-4542 CVE-2016-4543 CVE-2016-5385 CVE-2016-5387 CVE-2016-538809 Nov 2016 8.8 (v3) High Pass Bitrix Product and Modules Detection 02 May 2017 None Pass Open Source Point Of Sale Detection 07 Apr 2016 None Pass Rockwell Automation MicroLogix 1400 PLC Web Server Detection 20 Apr 2016 None 48
RELAYTO Penetration Test Results Page 47 Page 49