This page lists publicly disclosed CVE vulnerabilities affecting krontech single_connect (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-0882 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16. | [email protected] | 8.8 | 0.30% | 2023-02-17 | 2026-06-01 |
| CVE-2021-44795 | Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitation of this vulnerability might allow a remote attacker to delete permissions from other users without authenticating. | [email protected] | 5.3 | 0.13% | 2022-01-27 | 2026-05-18 |
| CVE-2021-44794 | Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information. | [email protected] | 5.3 | 0.18% | 2022-01-27 | 2026-05-18 |
| CVE-2021-44793 | Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials. | [email protected] | 8.6 | 0.57% | 2022-01-27 | 2026-05-18 |
| CVE-2021-44792 | Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to access the logging interface. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information. | [email protected] | 5.3 | 0.50% | 2022-01-27 | 2026-05-18 |