Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Lansweeper/
  3. Lansweeper Asset Discovery

Lansweeper Asset Discovery

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 19 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Auto-discovers and catalogs IT, OT, IoT, and cloud assets across networks.

by Lansweeper · lansweeper.com · source ↗

Known CVEs (19)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-39031 ↗MEDIUM 5.52026

    Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix is stored in cleartext alongside the ciphertext. T…

  • CVE-2022-32763 ↗MEDIUM 6.12022

    A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javasc…

  • CVE-2022-32573 ↗CRITICAL 9.92022

    A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attac…

  • CVE-2022-29517 ↗CRITICAL 9.92022

    A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload.…

  • CVE-2022-29511 ↗MEDIUM 6.52022

    A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary f…

  • CVE-2022-28703 ↗MEDIUM 5.42022

    A stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrar…

  • CVE-2022-27498 ↗MEDIUM 6.52022

    A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitra…

  • CVE-2022-22149 ↗HIGH 8.82022

    A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an…

  • CVE-2022-21234 ↗HIGH 8.82022

    An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenti…

  • CVE-2022-21210 ↗HIGH 8.82022

    An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authen…

  • CVE-2022-21145 ↗MEDIUM 4.82022

    A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrary Javascript code in…

  • CVE-2020-13658 ↗HIGH 8.02020

    In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.

  • CVE-2020-14011 ↗CRITICAL 9.82020

    Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution …

  • CVE-2019-18955 ↗MEDIUM 6.12019

    The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.

  • CVE-2019-13462 ↗CRITICAL 9.12019

    Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.

  • CVE-2015-9264 ↗CRITICAL 9.82018

    Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windows service.

  • CVE-2017-16841 ↗MEDIUM 6.12017

    LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.

  • CVE-2017-13706 ↗CRITICAL 9.92017

    XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, …

  • CVE-2017-9292 ↗MEDIUM 6.12017

    Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782.

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Cyber Asset Attack Surface Management (CAASM) products

see all →
  • Absolute Visibility · Absolute
  • AlgoSec AppViz · AlgoSec
  • ApexaiQ · ApexaiQ
  • Armis Centrix™ Asset Intelligence Engine · Armis
  • Armis Centrix™ for Asset Management and Security · Armis
  • Attack Surface Management · Liongard
  • Axonius Asset Management · Axonius
  • Axonius Cyber Asset Management · Axonius