AVer records
4 published records for vendor aver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-6536No exploit | The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access resaver · eh6108h\+ firmware · CWE-264 | Critical9.8 | — | 2.6% | Sep 18, 2016 |
40Plan | CVE-2016-6535No exploit | AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root accessaver · eh6108h\+ firmware · CWE-798 | Critical9.8 | — | 2.3% | Sep 18, 2016 |
30Monitor | CVE-2016-6537No exploit | AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentiaaver · eh6108h\+ firmware · CWE-200 | High7.5 | — | 1.3% | Sep 18, 2016 |
30Monitor | CVE-2023-27055No exploit | Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.aver · ptzapp 2 · CWE-22 | High7.5 | — | 0.7% | Mar 24, 2023 |
- CVE-2016-653640Plan
The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access res
CriticalCVSS 9.8No exploitEPSS 3%aver · eh6108h\+ firmwareSep 18, 2016
- CVE-2016-653540Plan
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access
CriticalCVSS 9.8No exploitEPSS 2%aver · eh6108h\+ firmwareSep 18, 2016
- CVE-2016-653730Monitor
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentia
HighCVSS 7.5No exploitEPSS 1%aver · eh6108h\+ firmwareSep 18, 2016
- CVE-2023-2705530Monitor
Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.
HighCVSS 7.5No exploitEPSS 1%aver · ptzapp 2Mar 24, 2023