← volver
CVE-2026-6348

Simopro Technology|WinMatrix - Missing Authentication

CVSS 9.3 CRITICALEPSS 0.2%CWE-306
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.3EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
16 abr 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →