ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

OnTrac is the solution of choice for last-mile e-commerce deliveries that helps retailers and shippers build a competitive advantage through faster delivery times, lower costs, coast-to-coast coverage, and reliable on-time performance. OnTrac’s footprint stretches across the United States to reach approximately 70% of the population in 35 states and Washington, D.C. and enhance retailers’ ability to meet growing demand in the consumer e-commerce delivery market. OnTrac has evolved into a critical part of the e-commerce infrastructure and is trusted by leading retailers and shippers that desire reduced transit times and increased flexibility within their supply chains.

OnTrac A.I CyberSecurity Scoring

OnTrac

Company Details

Linkedin ID:

ontrac-shipping

Employees number:

5,355

Number of followers:

27,516

NAICS:

47

Industry Type:

Transportation, Logistics, Supply Chain and Storage

Homepage:

ontrac.com

IP Addresses:

0

Company ID:

ONT_3173145

Scan Status:

In-progress

AI scoreOnTrac Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/ontrac-shipping.jpeg
OnTrac Transportation, Logistics, Supply Chain and Storage
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreOnTrac Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/ontrac-shipping.jpeg
OnTrac Transportation, Logistics, Supply Chain and Storage
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

OnTrac Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
OnTracBreach8544/2025
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: In April 2025, U.S. delivery company OnTrac suffered a data breach exposing sensitive personal information of over 40,000 individuals. The compromised data included names, dates of birth, Social Security numbers, driver’s license or state IDs, and medical/health insurance details. Attackers accessed the company’s network between April 13th and 15th, 2025, though OnTrac claims the data was re-secured and not distributed, with no evidence of misuse or fraud thus far. Despite this, the exposed information could enable malicious activities such as medical identity theft (e.g., fraudulent insurance claims, prescription drug resale), financial fraud (e.g., fake bank accounts, tax returns), or benefits theft. OnTrac responded by offering affected individuals 12 months of free credit monitoring and identity protection services via TransUnion and CyberScout. While the company acted swiftly to mitigate risks, the breach highlights the persistent threat of identity theft and the need for vigilance against phishing and social engineering attacks.

OnTrac
Breach
Severity: 85
Impact: 4
Seen: 4/2025
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: In April 2025, U.S. delivery company OnTrac suffered a data breach exposing sensitive personal information of over 40,000 individuals. The compromised data included names, dates of birth, Social Security numbers, driver’s license or state IDs, and medical/health insurance details. Attackers accessed the company’s network between April 13th and 15th, 2025, though OnTrac claims the data was re-secured and not distributed, with no evidence of misuse or fraud thus far. Despite this, the exposed information could enable malicious activities such as medical identity theft (e.g., fraudulent insurance claims, prescription drug resale), financial fraud (e.g., fake bank accounts, tax returns), or benefits theft. OnTrac responded by offering affected individuals 12 months of free credit monitoring and identity protection services via TransUnion and CyberScout. While the company acted swiftly to mitigate risks, the breach highlights the persistent threat of identity theft and the need for vigilance against phishing and social engineering attacks.

Ailogo

OnTrac Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for OnTrac

Incidents vs Transportation, Logistics, Supply Chain and Storage Industry Average (This Year)

OnTrac has 16.67% fewer incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

OnTrac has 28.21% more incidents than the average of all companies with at least one recorded incident.

Incident Types OnTrac vs Transportation, Logistics, Supply Chain and Storage Industry Avg (This Year)

OnTrac reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.

Incident History — OnTrac (X = Date, Y = Severity)

OnTrac cyber incidents detection timeline including parent company and subsidiaries

OnTrac Company Subsidiaries

SubsidiaryImage

OnTrac is the solution of choice for last-mile e-commerce deliveries that helps retailers and shippers build a competitive advantage through faster delivery times, lower costs, coast-to-coast coverage, and reliable on-time performance. OnTrac’s footprint stretches across the United States to reach approximately 70% of the population in 35 states and Washington, D.C. and enhance retailers’ ability to meet growing demand in the consumer e-commerce delivery market. OnTrac has evolved into a critical part of the e-commerce infrastructure and is trusted by leading retailers and shippers that desire reduced transit times and increased flexibility within their supply chains.

Loading...
similarCompanies

OnTrac Similar Companies

Aramex

Founded in 1982, Aramex has emerged as a global leader in logistics and transportation, renowned for its innovative services tailored to businesses and consumers. As a listed company on the Dubai Financial Market (since 2005) and headquartered in the UAE, our strategic location facilitates extensive

DHL is the leading global brand in the logistics industry. Our divisions offer an unrivaled portfolio of logistics services ranging from national and international parcel delivery, e-commerce shipping and fulfillment solutions, international express, road, air and ocean transport to industrial suppl

Kuehne+Nagel

With more than 82,000 employees at almost 1,300 sites in close to 100 countries, the Kuehne+Nagel Group is one of the world's leading logistics providers. Headquartered in Switzerland, Kuehne+Nagel is listed in the Swiss blue-chip stock market index, the SMI. The Group is the global number one in

A.P. Moller - Maersk

A.P. Moller - Maersk is an integrated transport and logistics company; going all the way, together, for our customers and society. ALL THE WAY is our commitment to connect the world so that everyone has both the possibility and the ability to trade, grow and thrive. The company employs roughly 110.0

CTT - Correios de Portugal

Os CTT assumem-se como uma empresa orientada para o cliente, com uma oferta segmentada para empresas e particulares, com soluções que começam no envio de correio e expresso (encomendas), que passam pelas melhores ofertas de poupanças e por um portefólio alargado de produtos e serviços empresariais,

Evri

Need some help? Get in touch with our friendly team at https://bit.ly/evriwebsite3 Every parcel, every person, every place. Evri is the UK’s biggest dedicated parcel delivery company, leading the way in creating responsible delivery experiences for everyone, everywhere. And we’re doing that by offe

DP World

Trade is the lifeblood of the global economy, creating opportunities and improving the quality of life for people around the world. DP World exists to make the world’s trade flow better, changing what’s possible for the customers and communities we serve globally. With a dedicated, diverse and p

MSC Mediterranean Shipping Company

MSC is a privately owned global shipping company founded in 1970 by Gianluigi Aponte. As one of the world’s leading container shipping lines with headquarters in Geneva, Switzerland, MSC operates in over 675 offices across more than 155 countries worldwide with over 200,000 MSC Group employees. With

Lineage is one of the world’s leading temperature-controlled industrial REITs and integrated solutions providers with a global network of over 480 strategically located facilities, totaling nearly 2.9 billion cubic feet of capacity across countries in North America, Europe, and Asia-Pacific. Couplin

newsone

OnTrac CyberSecurity News

September 12, 2025 07:00 AM
Vietnam confirms cyberattack on national credit data center as investigators assess scope of breach and stolen data

Vietnam's National Credit Information Center (CIC), which operates under the State Bank of Vietnam, has confirmed a cyberattack that may...

August 31, 2025 07:00 AM
News - OnTrac Data Breach Exposes Personal Information of Over 40,000 Individuals

American delivery company OnTrac Final Mile said the data security incident it suffered earlier this year compromised the sensitive personal...

August 30, 2025 07:00 AM
Thousands exposed via data breach of major American delivery company

OnTrac, a last-mile delivery company, has suffered a hacker attack. The attackers obtained personal details, including IDs,...

August 29, 2025 07:00 AM
OnTrac Data Breach Investigation

If you were affected by the OnTrac data breach, you may be entitled to compensation.

June 25, 2025 07:00 AM
Frontdoor Announces Tech Expert Dr. Bala Ganesh as Chief Technology Officer

Frontdoor, Inc. (NASDAQ: FTDR), the nation's leading provider of home warranties, today announced that Dr. Bala Ganesh has been selected to...

December 01, 2024 08:00 AM
Best early Cyber Monday Dyson deals: Save on vacuums, hair products, and more

The best Dyson Black Friday deals include our vacuum expert's favorite stick vac and our beauty reporter's favorite hair tools.

November 14, 2024 08:00 AM
Tackling Swivel Chair Syndrome

Ajit dives into CrowdStrike's innovative approach, from leveraging AI to simplify workflows to implementing automation that frees up analysts to focus on the...

September 23, 2024 07:00 AM
Dyson OnTrac headphones launched in India

The new Dyson OnTrac headphones boasts a custom Active Noise Cancellation (ANC) algorithm which uses 8 microphones, sampling external sound...

December 05, 2023 08:00 AM
Ethical Considerations in AI-Powered Cybersecurity

AI-powered cybersecurity is turbocharging the defenses of many organizations. System analysis and anomaly detection are getting smarter,...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

OnTrac CyberSecurity History Information

Official Website of OnTrac

The official website of OnTrac is https://www.ontrac.com.

OnTrac’s AI-Generated Cybersecurity Score

According to Rankiteo, OnTrac’s AI-generated cybersecurity score is 707, reflecting their Moderate security posture.

How many security badges does OnTrac’ have ?

According to Rankiteo, OnTrac currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does OnTrac have SOC 2 Type 1 certification ?

According to Rankiteo, OnTrac is not certified under SOC 2 Type 1.

Does OnTrac have SOC 2 Type 2 certification ?

According to Rankiteo, OnTrac does not hold a SOC 2 Type 2 certification.

Does OnTrac comply with GDPR ?

According to Rankiteo, OnTrac is not listed as GDPR compliant.

Does OnTrac have PCI DSS certification ?

According to Rankiteo, OnTrac does not currently maintain PCI DSS compliance.

Does OnTrac comply with HIPAA ?

According to Rankiteo, OnTrac is not compliant with HIPAA regulations.

Does OnTrac have ISO 27001 certification ?

According to Rankiteo,OnTrac is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of OnTrac

OnTrac operates primarily in the Transportation, Logistics, Supply Chain and Storage industry.

Number of Employees at OnTrac

OnTrac employs approximately 5,355 people worldwide.

Subsidiaries Owned by OnTrac

OnTrac presently has no subsidiaries across any sectors.

OnTrac’s LinkedIn Followers

OnTrac’s official LinkedIn profile has approximately 27,516 followers.

NAICS Classification of OnTrac

OnTrac is classified under the NAICS code 47, which corresponds to Transportation and Warehousing.

OnTrac’s Presence on Crunchbase

No, OnTrac does not have a profile on Crunchbase.

OnTrac’s Presence on LinkedIn

Yes, OnTrac maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/ontrac-shipping.

Cybersecurity Incidents Involving OnTrac

As of December 26, 2025, Rankiteo reports that OnTrac has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

OnTrac has an estimated 6,303 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at OnTrac ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does OnTrac detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes (data re-secured), and third party assistance with transunion, third party assistance with cyberscout (for identity protection services), and containment measures with data re-secured to prevent further access or distribution, and recovery measures with 12 months of free credit monitoring and identity protection services for affected individuals, and communication strategy with data breach notification letters sent to affected individuals; public disclosure via maine attorney general’s office..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: OnTrac Data Breach (April 2025)

Description: Thousands of people had their sensitive personal information exposed in a data breach at U.S. delivery company OnTrac that occurred over two days in April 2025. The breach impacted over 40,000 individuals, exposing personal details such as names, dates of birth, Social Security numbers, driver’s license or state IDs, and medical/health insurance information. The attackers had access to OnTrac's network between April 13th and April 15th, 2025. While OnTrac claims the data was re-secured and not distributed, the exposed information could be used for medical identity theft, fraudulent insurance claims, or other forms of identity theft.

Type: Data Breach

Motivation: Financial GainData Theft

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach ONT537090325

Data Compromised: Names, Dates of birth, Social security numbers, Driver’s license/state ids, Medical/health insurance information

Brand Reputation Impact: Potential reputational damage due to exposure of sensitive customer data

Identity Theft Risk: High (medical identity theft, fraudulent insurance claims, false tax returns, bank account fraud)

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Protected Health Information (Phi) and .

Which entities were affected by each incident ?

Incident : Data Breach ONT537090325

Entity Name: OnTrac

Entity Type: Delivery Company

Industry: Logistics/Transportation

Location: United States

Customers Affected: 40,000+ individuals

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach ONT537090325

Incident Response Plan Activated: Yes (data re-secured)

Third Party Assistance: Transunion, Cyberscout (For Identity Protection Services).

Containment Measures: Data re-secured to prevent further access or distribution

Recovery Measures: 12 months of free credit monitoring and identity protection services for affected individuals

Communication Strategy: Data breach notification letters sent to affected individuals; public disclosure via Maine Attorney General’s office

What is the company's incident response plan?

Incident Response Plan: The company's incident response plan is described as Yes (data re-secured).

How does the company involve third-party assistance in incident response ?

Third-Party Assistance: The company involves third-party assistance in incident response through TransUnion, CyberScout (for identity protection services), .

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach ONT537090325

Type of Data Compromised: Personally identifiable information (pii), Protected health information (phi)

Number of Records Exposed: 40,000+

Sensitivity of Data: High (includes SSNs, medical/health insurance data)

Data Exfiltration: Unconfirmed (OnTrac claims data was not distributed)

Personally Identifiable Information: NamesDates of BirthSocial Security NumbersDriver’s License/State IDs

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by data re-secured to prevent further access or distribution.

Ransomware Information

How does the company recover data encrypted by ransomware ?

Data Recovery from Ransomware: The company recovers data encrypted by ransomware through 12 months of free credit monitoring and identity protection services for affected individuals, .

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Data Breach ONT537090325

Regulatory Notifications: Maine Attorney General’s office (sample breach notification letter obtained)

Lessons Learned and Recommendations

What recommendations were made to prevent future incidents ?

Incident : Data Breach ONT537090325

Recommendations: Invest in identity theft protection services (e.g., TransUnion, CyberScout)., Use antivirus software with VPN and privacy protections., Monitor accounts for suspicious activity (e.g., fraudulent claims, unauthorized transactions)., Stay vigilant against phishing/social engineering (avoid clicking links/attachments from unknown senders)., Leverage free credit monitoring services offered post-breach.Invest in identity theft protection services (e.g., TransUnion, CyberScout)., Use antivirus software with VPN and privacy protections., Monitor accounts for suspicious activity (e.g., fraudulent claims, unauthorized transactions)., Stay vigilant against phishing/social engineering (avoid clicking links/attachments from unknown senders)., Leverage free credit monitoring services offered post-breach.Invest in identity theft protection services (e.g., TransUnion, CyberScout)., Use antivirus software with VPN and privacy protections., Monitor accounts for suspicious activity (e.g., fraudulent claims, unauthorized transactions)., Stay vigilant against phishing/social engineering (avoid clicking links/attachments from unknown senders)., Leverage free credit monitoring services offered post-breach.Invest in identity theft protection services (e.g., TransUnion, CyberScout)., Use antivirus software with VPN and privacy protections., Monitor accounts for suspicious activity (e.g., fraudulent claims, unauthorized transactions)., Stay vigilant against phishing/social engineering (avoid clicking links/attachments from unknown senders)., Leverage free credit monitoring services offered post-breach.Invest in identity theft protection services (e.g., TransUnion, CyberScout)., Use antivirus software with VPN and privacy protections., Monitor accounts for suspicious activity (e.g., fraudulent claims, unauthorized transactions)., Stay vigilant against phishing/social engineering (avoid clicking links/attachments from unknown senders)., Leverage free credit monitoring services offered post-breach.

References

Where can I find more information about each incident ?

Incident : Data Breach ONT537090325

Source: Cybernews

Incident : Data Breach ONT537090325

Source: Office of the Maine Attorney General

Incident : Data Breach ONT537090325

Source: Tom's Guide

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Cybernews, and Source: Office of the Maine Attorney General, and Source: Tom's Guide.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Breach ONT537090325

Investigation Status: Ongoing (no confirmed misuse of data reported by OnTrac)

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Data breach notification letters sent to affected individuals; public disclosure via Maine Attorney General’s office.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Data Breach ONT537090325

Stakeholder Advisories: Data breach notification letters sent to affected individuals

Customer Advisories: 12 months of free credit monitoring and identity protection via TransUnion/CyberScout.Guidance on protecting against identity theft (e.g., monitoring accounts, avoiding phishing).

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Data breach notification letters sent to affected individuals, 12 Months Of Free Credit Monitoring And Identity Protection Via Transunion/Cyberscout., Guidance On Protecting Against Identity Theft (E.G., Monitoring Accounts, Avoiding Phishing). and .

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Data Breach ONT537090325

High Value Targets: Customer Pii/Phi,

Data Sold on Dark Web: Customer Pii/Phi,

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach ONT537090325

Corrective Actions: Data Re-Securing, Provision Of Identity Protection Services To Affected Individuals,

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Transunion, Cyberscout (For Identity Protection Services), .

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Data Re-Securing, Provision Of Identity Protection Services To Affected Individuals, .

Additional Questions

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Names, Dates of Birth, Social Security Numbers, Driver’s License/State IDs, Medical/Health Insurance Information and .

Response to the Incidents

What third-party assistance was involved in the most recent incident ?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was transunion, cyberscout (for identity protection services), .

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Data re-secured to prevent further access or distribution.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Names, Driver’s License/State IDs, Social Security Numbers, Dates of Birth and Medical/Health Insurance Information.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 40.0K.

Lessons Learned and Recommendations

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Monitor accounts for suspicious activity (e.g., fraudulent claims, unauthorized transactions)., Leverage free credit monitoring services offered post-breach., Stay vigilant against phishing/social engineering (avoid clicking links/attachments from unknown senders)., Use antivirus software with VPN and privacy protections., Invest in identity theft protection services (e.g., TransUnion and CyberScout)..

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Tom's Guide, Cybernews and Office of the Maine Attorney General.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (no confirmed misuse of data reported by OnTrac).

Stakeholder and Customer Advisories

What was the most recent stakeholder advisory issued ?

Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Data breach notification letters sent to affected individuals, .

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued were an 12 months of free credit monitoring and identity protection via TransUnion/CyberScout.Guidance on protecting against identity theft (e.g., monitoring accounts and avoiding phishing).

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

Risk Information
cvss3
Base: 8.9
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Description

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and availability.

Risk Information
cvss3
Base: 5.6
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Description

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

Risk Information
cvss3
Base: 6.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=ontrac-shipping' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge