cbc records
4 published records for vendor cbc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-912 Hidden Functionality1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2023-40144No exploit | OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the devicbc · nr4h firmware · CWE-78 | High8.8 | — | 2.1% | Aug 23, 2023 |
35Monitor | CVE-2023-40158No exploit | Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the devicbc · nr4h firmware · CWE-912 | High8.8 | — | 1.3% | Aug 22, 2023 |
35Monitor | CVE-2023-38585No exploit | Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the dcbc · nr4h firmware · CWE-287 | High8.8 | — | 1.1% | Aug 22, 2023 |
21Monitor | CVE-2019-19464No exploit | The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.cbc · gem · CWE-311 | Medium5.3 | — | 0.5% | Nov 29, 2019 |
- CVE-2023-4014436Monitor
OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the devi
HighCVSS 8.8No exploitEPSS 2%cbc · nr4h firmwareAug 23, 2023
- CVE-2023-4015835Monitor
Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the devi
HighCVSS 8.8No exploitEPSS 1%cbc · nr4h firmwareAug 22, 2023
- CVE-2023-3858535Monitor
Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the d
HighCVSS 8.8No exploitEPSS 1%cbc · nr4h firmwareAug 22, 2023
- CVE-2019-1946421Monitor
The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.
MediumCVSS 5.3No exploitEPSS 1%cbc · gemNov 29, 2019