mersive records
7 published records for vendor mersive.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-307 Improper Restriction of Excessive Authentication Attempts2
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-12945Proof of concept | Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers tomersive · solstice firmware · CWE-78 | High8.8 | — | 17.5% | Nov 27, 2019 |
31Monitor | CVE-2020-27523No exploit | Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_namersive · solstice pod firmware · CWE-134 | High7.5 | — | 2.0% | Nov 11, 2020 |
30Monitor | CVE-2020-35587No exploit | In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled.mersive · solstice firmware · CWE-311 | High7.5 | — | 1.5% | Dec 23, 2020 |
30Monitor | CVE-2020-35585No exploit | In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Conmersive · solstice pod firmware · CWE-307 | High7.5 | — | 1.4% | Dec 23, 2020 |
30Monitor | CVE-2020-35586No exploit | In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/inmersive · solstice pod firmware · CWE-307 | High7.5 | — | 1.4% | Dec 23, 2020 |
27Monitor | CVE-2025-66573No exploit | Solstice Pod API Session Key Extraction via API Endpointmersive · solstice pod firmware · CWE-319 | Medium6.9 | — | 0.3% | Dec 4, 2025 |
23Monitor | CVE-2020-35584No exploit | In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature.mersive · solstice pod firmware · CWE-319 | Medium5.9 | — | 0.8% | Dec 23, 2020 |
- CVE-2017-1294540Plan
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to
HighCVSS 8.8Proof of conceptEPSS 17%mersive · solstice firmwareNov 27, 2019
- CVE-2020-2752331Monitor
Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_na
HighCVSS 7.5No exploitEPSS 2%mersive · solstice pod firmwareNov 11, 2020
- CVE-2020-3558730Monitor
In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled.
HighCVSS 7.5No exploitEPSS 1%mersive · solstice firmwareDec 23, 2020
- CVE-2020-3558530Monitor
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Con
HighCVSS 7.5No exploitEPSS 1%mersive · solstice pod firmwareDec 23, 2020
- CVE-2020-3558630Monitor
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/in
HighCVSS 7.5No exploitEPSS 1%mersive · solstice pod firmwareDec 23, 2020
- CVE-2025-6657327Monitor
Solstice Pod API Session Key Extraction via API Endpoint
MediumCVSS 6.9No exploitEPSS 0%mersive · solstice pod firmwareDec 4, 2025
- CVE-2020-3558423Monitor
In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature.
MediumCVSS 5.9No exploitEPSS 1%mersive · solstice pod firmwareDec 23, 2020