Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2024-36396

Disclosure Date: June 13, 2024 (last updated August 08, 2024)
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type
Attacker Value
Unknown

CVE-2024-36395

Disclosure Date: June 13, 2024 (last updated July 20, 2024)
Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Attacker Value
Unknown

CVE-2023-33257

Disclosure Date: August 02, 2023 (last updated October 08, 2023)
Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.
Attacker Value
Unknown

CVE-2020-12744

Disclosure Date: October 20, 2022 (last updated October 08, 2023)
The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.
Attacker Value
Unknown

CVE-2021-36450

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
Attacker Value
Unknown

CVE-2021-41825

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
Attacker Value
Unknown

CVE-2020-23446

Disclosure Date: September 22, 2020 (last updated February 22, 2025)
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
Attacker Value
Unknown

CVE-2020-24056

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.
Attacker Value
Unknown

CVE-2020-24055

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.
Attacker Value
Unknown

CVE-2020-24057

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filtering on the unit. This endpoint is vulnerable to a command injection. An authenticated attacker can leverage this issue to execute arbitrary commands as 'root'.