Записи iwt
7 опубликованных записей вендора iwt.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2019-25241Эксплойта нет | FaceSentry Access Control System 6.4.8 Remote SSH Root Accessiwt · facesentry access control system firmware · CWE-798 | Критическая9,8 | — | 0,7 % | 24 дек. 2025 г. |
37Наблюдать | CVE-2020-21999Эксплойта нет | iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials.iwt · facesentry access control system firmware · CWE-78 | Высокая8,8 | — | 5,2 % | 4 мая 2021 г. |
36Наблюдать | CVE-2019-25278Эксплойта нет | FaceSentry Access Control System 6.4.8 Authentication Credentials MiTM Disclosureiwt · facesentry access control system firmware · CWE-319 | Критическая9,1 | — | 0,3 % | 7 янв. 2026 г. |
35Наблюдать | CVE-2019-25243Эксплойта нет | FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Testiwt · facesentry access control system firmware · CWE-78 | Высокая8,7 | — | 2,6 % | 24 дек. 2025 г. |
27Наблюдать | CVE-2019-25279Эксплойта нет | FaceSentry Access Control System 6.4.8 Cleartext Password Storage Vulnerabilityiwt · facesentry access control system firmware · CWE-312 | Средняя6,8 | — | 0,2 % | 7 янв. 2026 г. |
20Наблюдать | CVE-2019-25277Эксплойта нет | FaceSentry Access Control System 6.4.8 Reflected Cross-Site Scripting via pluginInstall.phpiwt · facesentry access control system firmware · CWE-79 | Средняя5,1 | — | 0,3 % | 7 янв. 2026 г. |
20Наблюдать | CVE-2019-25242Эксплойта нет | FaceSentry Access Control System 6.4.8 Cross-Site Request Forgery via Web Interfaceiwt · facesentry access control system firmware · CWE-352 | Средняя5,1 | — | 0,2 % | 24 дек. 2025 г. |
- CVE-2019-2524139Наблюдать
FaceSentry Access Control System 6.4.8 Remote SSH Root Access
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iwt · facesentry access control system firmware24 дек. 2025 г.
- CVE-2020-2199937Наблюдать
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials.
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %iwt · facesentry access control system firmware4 мая 2021 г.
- CVE-2019-2527836Наблюдать
FaceSentry Access Control System 6.4.8 Authentication Credentials MiTM Disclosure
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %iwt · facesentry access control system firmware7 янв. 2026 г.
- CVE-2019-2524335Наблюдать
FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test
ВысокаяCVSS 8,7Эксплойта нетEPSS 3 %iwt · facesentry access control system firmware24 дек. 2025 г.
- CVE-2019-2527927Наблюдать
FaceSentry Access Control System 6.4.8 Cleartext Password Storage Vulnerability
СредняяCVSS 6,8Эксплойта нетEPSS 0 %iwt · facesentry access control system firmware7 янв. 2026 г.
- CVE-2019-2527720Наблюдать
FaceSentry Access Control System 6.4.8 Reflected Cross-Site Scripting via pluginInstall.php
СредняяCVSS 5,1Эксплойта нетEPSS 0 %iwt · facesentry access control system firmware7 янв. 2026 г.
- CVE-2019-2524220Наблюдать
FaceSentry Access Control System 6.4.8 Cross-Site Request Forgery via Web Interface
СредняяCVSS 5,1Эксплойта нетEPSS 0 %iwt · facesentry access control system firmware24 дек. 2025 г.