RIPEDA Consulting

Recent Disclosures

Here's a sample of vulnerabilities we've identified and responsibly disclosed:

Reference IDProductAffected VersionsDescription
CVE-2024-27822macOS14.4.1 and olderLocal Privilege Escalation
CVE-2024-34331Parallels Desktop19.3.0 and olderLocal Privilege Escalation
CVE-2024-4395Jamf Compliance Editor1.3.0 and olderLocal Privilege Escalation
CVE-2024-25545Weave DesktopUnresolvedArbitrary Code Execution
Synology-SA-24:05Synology Surveillance Station Client2.1.3-2474 and olderArbitrary Code Execution
CVE-2024-23755ClickUp Desktop App3.3.76 and olderArbitrary Code Execution
CVE-2023-50975TD Advanced Dashboard3.0.3 and olderArbitrary Code Execution
CVE-2023-7245OpenVPN3.4.7 and olderArbitrary Code Execution
CVE-2023-44077ShareBrowser XPC Services6.1.5.27 and olderLocal Privilege Escalation

Responsible Disclosure Policy

RIPEDA Consulting is committed to responsible disclosure of security vulnerabilities we discover.

90-Day Disclosure Timeline

We follow Google's Project Zero guidelines with a 90+30 disclosure deadline policy. Vendors have 90 days to patch vulnerabilities after initial notification.

User Protection Priority

If vendors patch within 90 days, we publicly disclose details 30 days after patch release. If no patch is available after 90 days, we disclose immediately to protect users.

Vendor Accountability

This process ensures vendors are held accountable for security while giving them reasonable time to fix issues and allowing users time to update their systems.

Reporting Security Vulnerabilities

Found a security vulnerability in our products or infrastructure?
We want to hear from you.

Report a Vulnerability

Email us immediately at info@ripeda.com with:

  • Detailed steps to reproduce the vulnerability
  • Affected versions of the product
  • Any relevant technical information
  • Your contact information for follow-up