Known Vulnerabilities for products from Nch

Listed below are 9 of the newest known vulnerabilities associated with the vendor "Nch".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-37469 json In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the files... 6.5 - MEDIUM 2021-07-25 2021-08-05
CVE-2021-37468 json NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files. 3.3 - LOW 2021-07-25 2022-07-12
CVE-2021-37452 json NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the loca... 5.5 - MEDIUM 2021-07-25 2022-07-12
CVE-2021-37441 json NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring. 8.8 - HIGH 2021-07-25 2021-08-06
CVE-2021-37440 json NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring. 6.5 - MEDIUM 2021-07-25 2021-08-05
CVE-2021-37439 json NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability. 6.5 - MEDIUM 2021-07-25 2021-08-05
CVE-2018-11552 json There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability ex... 6.1 - MEDIUM 2018-06-01 2018-07-03
CVE-2018-11551 json AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrar... 7.8 - HIGH 2018-06-01 2018-07-03
CVE-2009-4038 json Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to ... Not Provided 2009-11-20 2026-04-23

Known software with vulnerabilities from Nch

Type Vendor Product Version
ApplicationNchAxon Pbx2.02

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report