Skip to main content
Compass SecurityCompass Security
Search
  • DE
  • EN
  • Current
    • News
    • Blog
    • Agenda
    • Advisories
  • Services
    • Test d'intrusion
    • Security Reviews
    • Red Teaming
    • Purple Teaming
    • Bug Bounty Managed Service
    • Managed Detection and Response
    • Réponse aux Incidents et Forensics
  • Products
    • FileBox
    • Hacking-Lab
  • Trainings
    • Digital Forensics and Incident Response (DFIR)
    • Internal Network and System Security
    • Internet of Things Security
    • Open Source Intelligence (OSINT)
    • Secure Mobile Apps
    • Security Boot Camp
    • Social Engineering
    • Web Application Security Advanced
    • Web Application Security Basic
  • Research
    • Advisories
    • White Paper
    • Presentations
    • Studies
  • Company
    • About us
    • Contact
    • Testimonials
    • Mailing list TIGER-INFO
    • Jobs
  • Contact
    • Free Initial Discussion
    • Sample Report
    • Locations
  • Emergency?
  • DE
  • EN
Search

You are here:

  1. Compass Security
  2. News
  3. Detail

Vulnerabilities on AdRem NetCrunch platform

09/12/2020

Thierry Viaccoz, Sylvain Heiniger and Fabio Poloni identified several vulnerabilities in the AdRem NetCrunch monitoring solution.

 

Details to these advisories:

CSNC-2019-011 / Server-Side Request Forgery (SSRF)

CSNC-2019-012 / Improper Credential Storage

CSNC-2019-013 / Cross-Site Scripting (XSS)

CSNC-2019-014 / Remote Code Execution

CSNC-2019-015 / Improper Session Handling

CSNC-2019-016 / Cross-Site Request Forgery (CSRF)

CSNC-2019-017 / Hardcoded SSL Private Key

CSNC-2019-018 / Credentials Disclosure

 

Retour

Blog

Continuous Learning – Inside our Internal Security Training

20.01.2026

Over the course of 2025, we performed several hundred security assessments for our clients. In each of these, security analysts must understand a new…

Lire la suite

Calendar

VIS Kontaktparty 2026

14.03.2026

On Saturday, 14 March, Switzerland’s next generation of IT professionals will gather at the VIS Contact Party, the largest academic IT recruiting fair…

Lire la suite

News

When Scammers Exploit Trust with AI

28.01.2026

Swiss broadcaster SRF is dedicating a full week to the theme "Fact or Fake?". In the show "Kassensturz", we had the chance to assist with an…

Lire la suite
  • Imprint
  • Legal
  • Sitemap
  • Deutsch
  • English
  • Twitter
  • GitHub
  • LinkedIn
  • RSS