Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Netwrix/
  3. Netwrix Endpoint Management

Netwrix Endpoint Management

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 20 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Endpoint management solution with privilege & device control policy enforcement

by Netwrix · netwrix.com · source ↗

Known CVEs (20)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-54396 ↗MEDIUM 5.42025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.

  • CVE-2025-54395 ↗MEDIUM 6.12025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.

  • CVE-2025-54394 ↗MEDIUM 5.32025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.

  • CVE-2025-54393 ↗MEDIUM 5.42025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.

  • CVE-2025-54392 ↗MEDIUM 6.12025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.

  • CVE-2025-47189 ↗MEDIUM 6.12025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data of certain user flows, a different vulnerability than CVE-2025-54392.

  • CVE-2025-48748 ↗CRITICAL 10.02025

    Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.

  • CVE-2025-48749 ↗CRITICAL 9.12025

    Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.

  • CVE-2025-48747 ↗MEDIUM 5.02025

    Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.

  • CVE-2025-47748 ↗MEDIUM 5.32025

    Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.

  • CVE-2025-48746 ↗MEDIUM 6.52025

    Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

  • CVE-2025-26818 ↗CRITICAL 9.82025

    Netwrix Password Secure through 9.2 allows command injection.

  • CVE-2025-26817 ↗CRITICAL 9.82025

    Netwrix Password Secure 9.2.0.32454 allows OS command injection.

  • CVE-2024-36074 ↗HIGH 7.22024

    Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in the way that the EasyLock de…

  • CVE-2024-36073 ↗HIGH 7.22024

    Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing component of the Endpoint Protector and Unify agent whic…

  • CVE-2024-36072 ↗CRITICAL 9.82024

    Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector and Unify server appli…

  • CVE-2023-41264 ↗CRITICAL 9.82023

    Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the conf…

  • CVE-2022-31199 ↗⚠ actively exploitedCRITICAL 9.82022

    Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remo…

  • CVE-2020-15931 ↗HIGH 7.52020

    Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its…

  • CVE-2019-14969 ↗HIGH 7.82019

    Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to th…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Endpoint Detection & Response products

see all →
  • 360 High-Risk Vulnerability Immunization Tool V2.0 · 360 Security Group (Qihoo 360)
  • AI EdgeLabs Host Platform Security · AI EdgeLabs
  • AVG AntiVirus FREE · AVG
  • AVG Antivirus Free for Mac · AVG
  • Abatis System · Abatis
  • Absolute Ransomware Response · Absolute
  • Absolute Resilience · Absolute
  • Absolute Resilience for Security · Absolute