Pass Acme thttpd Detection 14 Feb 2017 None Pass Default Password 'P@ssw0rd' for 'admin' Account CVE-1999-0502 10 Nov 2016 9.8 (v3) Critical Pass PowerFolder Server Detection 24 Jun 2016 None Pass BlackBerry Enterprise Service (BES) Management Console Detection 03 Jun 2016 None Pass Cisco UCS Central Software Web UI Detection 25 Aug 2016 None Pass Advantech WebAccess < 7.0-2011.08.27 Multiple ActiveX RCE 19 Aug 2015 6.8 (v2) Medium Pass Veritas NetBackup Appliance 2.6.0.x / 2.6.1.x / 2.7.x RCE (VTS16-002) CVE-2016-7399 10 Nov 2016 9.8 (v3) Critical Pass IBM Network Security Protection XGS Remote Code Execution (swg21690823) (credentialed attack) CVE-2014-6183 02 Jan 2015 4 (v2) Medium Pass IBM Network Security Protection XGS WebUI Detection 02 Jan 2015 None Pass Graylog2 Web Interface Detection 10 Feb 2015 None Pass Fortinet FortiAuthenticator Appliance Web Interface Detection 16 Feb 2015 None Pass .bash_history Files Disclosed via Web Server 12 May 2015 5.3 (v3) Medium Pass Siemens SCALANCE S612 Firewall > 2.1 and < 2.3.0.3 Multiple Vulnerabilities (SSA-268149) CVE-2012-1799 CVE-2012-1800 06 May 2015 10 (v2) Critical Pass Rockwell Automation MicroLogix 1100 PLC Web Server Detection 07 Jul 2015 None Pass Patch Management: Red Hat Satellite Server Settings 17 Jun 2015 None Pass Schneider Electric InduSoft Web Studio Detection 18 Jun 2015 None Pass Trend Micro Threat Intelligence Manager Web Console Detection 22 Jul 2015 None Pass XEROX ColorQube Device Detection 10 Oct 2013 None Pass ClearSCADA Web Server Remote Denial of Service 15 Oct 2013 7.8 (v2) High Pass Zimbra Collaboration Server Aspell Spell Check Service Detection 24 Feb 2014 None Pass Oracle WebCenter Sites Detection 03 Mar 2014 None Pass F5 Networks BIG-IQ Configuration Utility Login Page Detection 09 May 2014 None Pass Usermin Detection 16 Sep 2014 None Pass Novell GroupWise Administration Console Detection 02 Sep 2014 None Pass Novell File Reporter Agent XML Parsing Remote Code Execution CVE-2011-0994 10 Sep 2012 10 (v2) Critical Pass RuggedCom RuggedOS < 3.12.1 Web UI Multiple Security Vulnerabilities 06 Feb 2013 10 (v2) Critical Pass Patch Management: HCL BigFix Get Installed Packages 27 Mar 2013 None Pass Apple OS X Profile Manager Device Management Private Interface Managed Device Enumeration CVE-2012-3721 25 Mar 2013 5 (v2) Medium Pass Novell File Reporter Agent Detection 09 May 2011 None Pass Adobe Flex SDK Cross-Site Scripting (APSB11-25) (deprecated) CVE-2011-2461 01 Dec 2011 4.3 (v2) Medium Pass Do not scan printers 01 Dec 2003 None Pass Modicon Quantum HTTP Server Default Credentials 11 Dec 2006 7.5 (v2) High Pass Web mirroring 04 May 2001 None Pass Symantec Content Analysis Web Detection 21 May 2019 None Pass Jenkins Plugins Detection 20 Sep 2019 None Pass Drupal PHPUnit/Mailchimp Code Execution Vulnerability CVE-2017-9841 06 Sep 2019 9.8 (v3) Critical Pass Siemens SIMATIC S7-1200 PLC UDP Denial of Service (CVE-2019-10936) CVE-2019-10936 06 Dec 2019 7.5 (v3) High Pass Rancher Web Interface Detection 13 Dec 2018 None Pass Lenel OnGuard License Administrator 29 Jan 2019 None Pass Cisco Small Business Router Web UI Detection 23 Jul 2020 None Pass SAP NetWeaver : Authentication Bypass (CVE-2020-6287) (Direct Check) CVE-2020-6287 20 Jul 2020 10 (v3) Critical Pass Trend Micro InterScan Web Security Virtual Appliance Detection 28 Jul 2020 None Pass Apache Struts 2.x < 2.5.26 RCE (S2-061) (direct check) CVE-2020-17530 17 Dec 2020 9.8 (v3) Critical Pass Selligent Message Studio Struts Code Execution (CVE-2013-2251) CVE-2013-2251 05 Nov 2020 10 (v3) Critical Pass SonicWall Secure Mobile Access (SMA) Web Detection 03 Feb 2021 None Pass SAP Solution Manager Web Detection 26 Jan 2021 None Pass Apache Flink local file inclusion Vulnerability (direct check) CVE-2020-17519 09 Feb 2021 7.5 (v3) High Pass Apache Druid < 0.20.1 RCE (Direct Check) CVE-2021-25646 30 Mar 2021 8.8 (v3) High Pass SonicWall Email Security Web Interface Detected 26 Apr 2021 None Pass Trend Micro ServerProtect Information Server Detection 22 Oct 2021 None Pass Cisco Integrated Management Controller GUI DoS (cisco-sa-imc-gui-dos-TZjrFyZh) CVE-2021-34736 22 Oct 2021 7.5 (v3) High Pass Cisco IOS XE Software SD WAN Command Injection (cisco-sa-sd-wan-rhpbE34A) CVE-2021-1529 22 Oct 2021 7.8 (v3) High Pass PHP 5.4.x < 5.4.44 Multiple Vulnerabilities CVE-2015-6831 CVE-2015-6832 CVE-2015-6833 CVE-2015-8867 11 Aug 2015 7.3 (v3) High Pass Apache ActiveMQ Blob Message Directory Traversal CVE-2015-1830 21 Aug 2015 5 (v2) Medium Pass Cisco TelePresence VCS Expressway 8.5.3 XML External Entity (XXE) Injection CVE-2015-4315 26 Aug 2015 6.4 (v3) Medium Pass PHP 5.6.x < 5.6.28 Multiple Vulnerabilities CVE-2016-7478 CVE-2016-9933 CVE-2016-9934 18 Nov 2016 7.5 (v3) High Pass Cisco TelePresence VCS Expressway Series 8.5.1 Information Disclosure CVE-2015-4314 26 Aug 2015 4.3 (v3) Medium Pass Cisco TelePresence VCS Expressway Series 8.5.2 Multiple Vulnerabilities CVE-2015-4303 CVE-2015-4316 CVE-2015-4317 CVE-2015-4318 CVE-2015-4319 CVE-2015-4320 26 Aug 2015 6.3 (v3) Medium Pass CockroachDB < 2.1.10 / 19.x < 19.1.6 / 19.2.x < 19.2.2 Information Disclosure Direct Check (A44348) 04 Apr 2022 5.3 (v3) Medium Pass CockroachDB < 2.1.12 / 19.x < 19.1.8 / 19.2 < 19.2.4 Information Disclosure (A44348) 04 Apr 2022 5.3 (v3) Medium Pass CockroachDB < 2.1.10 / 19.1.x < 19.1.16 / 19.2.x < 19.2.2 Broken Access Control Vulnerability (A42567) 04 Apr 2022 9.1 (v3) Critical Pass PHP 5.4.x < 5.4.45 Multiple Vulnerabilities CVE-2014-9767 CVE-2015-6834 CVE-2015-6835 CVE-2015-6836 CVE-2015-6837 CVE-2015-6838 10 Sep 2015 7.3 (v3) High Pass PHP 5.5.x < 5.5.29 Multiple Vulnerabilities CVE-2014-9767 CVE-2015-6834 CVE-2015-6835 CVE-2015-6836 CVE-2015-6837 CVE-2015-6838 10 Sep 2015 7.3 (v3) High Pass PHP 5.6.x < 5.6.13 Multiple Vulnerabilities CVE-2014-9767 CVE-2015-6834 CVE-2015-6835 CVE-2015-6836 CVE-2015-6837 CVE-2015-6838 10 Sep 2015 7.3 (v3) High Pass Persistent Systems Radia Client Automation Agent Command Injection 25 Sep 2015 10 (v2) Critical Pass TLS Version 1.1 Protocol Deprecated 04 Apr 2022 6.5 (v3) Medium Pass PHP 5.5.x < 5.5.30 Multiple Vulnerabilities CVE-2015-7803 CVE-2015-7804 06 Oct 2015 8.6 (v3) High Pass OpenSSH PCI Disputed Vulnerabilities. CVE-2016-20012 CVE-2020-15778 CVE-2021-36368 04 Apr 2022 7.8 (v3) High Pass PHP 5.6.x < 5.6.14 Multiple Vulnerabilities CVE-2015-7803 CVE-2015-7804 06 Oct 2015 8.6 (v3) High Pass VISAM Automation Base (VBASE) Web-Remote Path Traversal (CVE-2020-7008) CVE-2020-7008 01 Mar 2022 7.5 (v3) High Pass VISAM Automation Base (VBASE) Web-Remote Detection 01 Mar 2022 None Pass Persistent Systems Radia Client Automation Agent Command Injection CVE-2015-1497 19 Oct 2015 10 (v2) Critical Pass DNN (DotNetNuke) < 7.4.2 Multiple Vulnerabilities 20 Oct 2015 4.3 (v2) Medium Pass Cisco TelePresence VCS Expressway 8.5.1 / 8.5.2 request-xconfdump Symbolic Link Local File Manipulation (cisco-sa-20141007-vcs)CVE-2015-6318 22 Oct 2015 9.3 (v3) Critical Pass 3S CODESYS Runtime Toolkit < 2.4.7.48 PLCWinNT DoS CVE-2015-6482 23 Oct 2015 5 (v2) Medium Pass Atlassian Bamboo 2.2.x < 5.8.5 / 5.9.x < 5.9.7 Unspecified Resource Deserialization RCE CVE-2015-6576 04 Nov 2015 8.8 (v3) High Pass nginx 1.9.x < 1.9.6 HTTPv2 PRI Double-Free DoS 16 Nov 2015 7.5 (v3) High Pass Jenkins < 1.638 / 1.625.2 Java Object Deserialization RCE CVE-2015-8103 17 Nov 2015 7.5 (v2) High Pass Crestron QM-RMC Service Detection 22 Dec 2015 None Pass PHP 7.0.x < 7.0.1 Multiple Vulnerabilities CVE-2015-8616 CVE-2015-8617 22 Dec 2015 9.8 (v3) Critical Pass Oracle E-Business Multiple Vulnerabilities (January 2016 CPU) CVE-2015-3195 CVE-2015-4926 CVE-2016-0454 CVE-2016-0456 CVE-2016-0457 CVE-2016-0459 CVE-2016-0507 CVE-2016-0509 CVE-2016-0510 CVE-2016-0511 CVE-2016-0512 CVE-2016-0513 CVE-2016-0514 CVE-2016-0515 CVE-2016-0516 CVE-2016-0517 CVE-2016-0518 CVE-2016-0519 CVE-2016-0520 CVE-2016-0521 CVE-2016-0523 CVE-2016-0524 CVE-2016-0525 CVE-2016-0526 CVE-2016-0527 CVE-2016-0528 CVE-2016-0529 CVE-2016-0530 CVE-2016-0531 CVE-2016-0532 CVE-2016-0533 CVE-2016-0534 CVE-2016-0536 CVE-2016-0537 CVE-2016-0538 CVE-2016-0539 CVE-2016-0542 CVE-2016-0543 CVE-2016-0544 CVE-2016-0545 CVE-2016-0547 CVE-2016-0548 CVE-2016-0549 CVE-2016-0550 CVE-2016-0551 CVE-2016-0552 CVE-2016-0553 CVE-2016-0554 CVE-2016-0555 CVE-2016-0556 CVE-2016-0557 CVE-2016-0558 CVE-2016-0559 CVE-2016-0560 CVE-2016-0561 CVE-2016-0562 CVE-2016-0563 CVE-2016-0564 CVE-2016-0565 CVE-2016-0566 CVE-2016-0567 CVE-2016-0568 CVE-2016-0569 CVE-2016-0570 CVE-2016-0571 CVE-2016-0575 CVE-2016-0576 CVE-2016-0578 CVE-2016-0579 CVE-2016-0580 CVE-2016-0581 CVE-2016-0582 CVE-2016-0583 CVE-2016-0584 CVE-2016-0585 CVE-2016-0586 CVE-2016-0588 CVE-2016-058921 Jan 2016 6.4 (v2) Medium Pass Cisco TelePresence VCS 8.5.1 Unspecified XSRF (cisco-sa-20151120-tvcs) CVE-2015-6376 02 Feb 2016 7.3 (v3) High Pass PHP prior to 5.5.x < 5.5.31 / 5.6.x < 5.6.17 Multiple Vulnerabilities CVE-2016-1903 CVE-2016-5114 10 Feb 2016 9.1 (v3) Critical Pass PHP 7.x < 7.0.2 Multiple Vulnerabilities CVE-2016-1903 CVE-2016-1904 CVE-2016-5114 10 Feb 2016 7.3 (v3) High Pass PHP 5.6.x < 5.6.18 Multiple Vulnerabilities CVE-2015-8383 CVE-2015-8386 CVE-2015-8387 CVE-2015-8389 CVE-2015-8390 CVE-2015-8391 CVE-2015-8393 CVE-2015-8394 CVE-2016-2554 CVE-2016-4342 CVE-2016-4343 CVE-2016-1071211 Feb 2016 9.8 (v3) Critical Pass Symantec Encryption Management Server 3.3.2 < 3.3.2 MP12 Multiple Vulnerabilities (SYM16-002) CVE-2015-8148 CVE-2015-8149 CVE-2015-8150 CVE-2015-8151 23 Feb 2016 7.8 (v3) High Pass Tenable Nessus < 6.5.5 Host Details Scan Results XSS CVE-2016-82000 23 Feb 2016 3.4 (v3) Low Pass Jenkins < 1.642.2 / 1.650 Java Object Deserialization RCE CVE-2016-0792 29 Feb 2016 8.8 (v3) High Pass Jenkins < 1.642.2 / 1.650 Java Object Deserialization RCE CVE-2016-0788 07 Mar 2016 9.8 (v3) Critical Pass Centreon Default Administrator Password 23 Dec 2014 7.5 (v2) High Pass PHP 5.4.x < 5.4.36 'process_nested_data' RCE CVE-2014-8142 02 Jan 2015 7.5 (v2) High Pass PHP 5.5.x < 5.5.20 'process_nested_data' RCE CVE-2014-8142 02 Jan 2015 7.5 (v2) High Pass Centreon 'insertLog()' Function RCE 05 Jan 2015 7.5 (v2) High Pass Dell iDRAC Products IPMI Arbitrary Command Injection Vulnerability CVE-2014-8272 09 Jan 2015 5 (v2) Medium Pass IBM Endpoint Manager Enrollment and Apple iOS Management Extender Detection 20 Jan 2015 None Pass IBM Tivoli Storage Manager Server 6.2 < 6.2.7 / 6.3 < 6.3.5 / 7.1 < 7.1.1 GSKit X.509 Certificate Chain DoSCVE-2013-6747 13 Jan 2015 7.1 (v2) High Pass Oracle OpenSSO SAML Multiple Vulnerabilities (January 2015 CPU) CVE-2014-6592 CVE-2015-0389 27 Jan 2015 3.5 (v2) Low Pass QNAP QTS / QuTS Hero Arbitrary Code Execution (QSA-21-57) 05 Apr 2022 9.8 (v3) Critical Pass Cisco IOS XR Software Border Gateway Protocol DoS (cisco-sa-20090818-bgp) CVE-2009-1154 CVE-2009-2055 CVE-2009-2056 05 Apr 2022 5.9 (v3) Medium Pass PHP 5.4.x < 5.4.37 Multiple Vulnerabilities CVE-2014-9427 CVE-2014-9652 CVE-2015-0231 CVE-2015-0232 29 Jan 2015 7.3 (v3) High Pass PHP 5.5.x < 5.5.21 Multiple Vulnerabilities CVE-2014-9425 CVE-2014-9427 CVE-2014-9652 CVE-2014-9709 CVE-2015-0231 CVE-2015-0232 29 Jan 2015 9.8 (v3) Critical Pass PHP 5.6.x < 5.6.5 Multiple Vulnerabilities CVE-2014-9425 CVE-2014-9427 CVE-2014-9652 CVE-2014-9709 CVE-2015-0231 CVE-2015-0232 29 Jan 2015 9.8 (v3) Critical Pass Cisco Catalyst PON Series Web Detection 15 Nov 2021 None Pass Apache 2.4.x < 2.4.12 Multiple Vulnerabilities CVE-2013-5704 CVE-2014-3581 CVE-2014-3583 CVE-2014-8109 02 Feb 2015 5.3 (v3) Medium Pass Pandora FMS <= 5.0 SP2 SQLi 03 Feb 2015 7.5 (v2) High Pass Default Password (changeme) for 'splunkadmin' Account CVE-1999-0502 04 Feb 2015 9.8 (v3) Critical Pass Symantec Encryption Management Server < 3.3.2 MP7 Multiple Vulnerabilities CVE-2014-7287 CVE-2014-7288 05 Feb 2015 9 (v2) High Pass Atmail Webmail Unsupported Version Detection 05 Feb 2015 10 (v2) Critical Pass Atmail Webmail 7.x < 7.2.2 Multiple Vulnerabilities 05 Feb 2015 6.8 (v2) Medium Pass FreePBX /recordings/index.php 'ari_auth' Cookie Authentication Bypass CVE-2014-7235 05 Feb 2015 10 (v2) Critical Pass DNN (DotNetNuke) < 7.4.0 Unspecified Persistent XSS CVE-2015-1566 12 Feb 2015 4.3 (v2) Medium Pass Apache ActiveMQ Web Console Default Credentials 16 Feb 2015 7.5 (v2) High 49
RELAYTO Penetration Test Results Page 48 Page 50