apsystems records
4 published records for vendor apsystems.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-284 Improper Access Control1
- CWE-345 Insufficient Verification of Data Authenticity1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2023-28343Proof of concept | OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezapsystems · energy communication unit firmware · CWE-78 | Critical9.8 | — | 84.8% | Mar 14, 2023 |
62This week | CVE-2022-45699Proof of concept | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrapsystems · ecu-r firmware · CWE-78 | Critical9.8 | — | 76.6% | Feb 9, 2023 |
35Monitor | CVE-2022-44037No exploit | An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allowapsystems · ecu-c firmware · CWE-284 | High8.8 | — | 0.6% | Nov 29, 2022 |
28Monitor | CVE-2023-31502No exploit | Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/manaapsystems · alternergy power control software · CWE-345 | High7.2 | — | 0.7% | May 11, 2023 |
- CVE-2023-2834364This week
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timez
CriticalCVSS 9.8Proof of conceptEPSS 85%apsystems · energy communication unit firmwareMar 14, 2023
- CVE-2022-4569962This week
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitr
CriticalCVSS 9.8Proof of conceptEPSS 77%apsystems · ecu-r firmwareFeb 9, 2023
- CVE-2022-4403735Monitor
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allow
HighCVSS 8.8No exploitEPSS 1%apsystems · ecu-c firmwareNov 29, 2022
- CVE-2023-3150228Monitor
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/mana
HighCVSS 7.2No exploitEPSS 1%apsystems · alternergy power control softwareMay 11, 2023