computrols records
10 published records for vendor computrols.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-798 Use of Hard-coded Credentials2
- CWE-326 Inadequate Encryption Strength1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-10850No exploit | Computrols CBAS 18.0.0 has Default Credentials.computrols · computrols building automation software · CWE-798 | Critical9.8 | — | 1.9% | May 23, 2019 |
36Monitor | CVE-2019-10854No exploit | Computrols CBAS 18.0.0 allows Authenticated Command Injection.computrols · computrols building automation software · CWE-77 | High8.8 | — | 3.0% | May 23, 2019 |
36Monitor | CVE-2019-10847Proof of concept | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.computrols · computrols building automation software · CWE-352 | High8.8 | — | 2.4% | May 24, 2019 |
36Monitor | CVE-2019-10852No exploit | Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=startcomputrols · computrols building automation software · CWE-89 | High8.8 | — | 1.8% | May 23, 2019 |
33Monitor | CVE-2019-10849Proof of concept | Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.computrols · computrols building automation software · CWE-862 | High7.5 | — | 9.0% | May 23, 2019 |
32Monitor | CVE-2019-10853No exploit | Computrols CBAS 18.0.0 allows Authentication Bypass.computrols · computrols building automation software | High8.1 | — | 1.7% | May 23, 2019 |
30Monitor | CVE-2019-10855No exploit | Computrols CBAS 18.0.0 mishandles password hashes.computrols · computrols building automation software · CWE-326 | High7.5 | — | 1.0% | May 23, 2019 |
26Monitor | CVE-2019-10851No exploit | Computrols CBAS 18.0.0 has hard-coded encryption keys.computrols · computrols building automation software · CWE-798 | Medium6.5 | — | 0.7% | May 23, 2019 |
25Monitor | CVE-2019-10846Proof of concept | Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via tcomputrols · computrols building automation system · CWE-79 | Medium6.1 | — | 4.7% | May 23, 2019 |
24Monitor | CVE-2019-10848Proof of concept | Computrols CBAS 18.0.0 allows Username Enumeration.computrols · computrols building automation software · CWE-203 | Medium5.3 | — | 8.5% | May 24, 2019 |
- CVE-2019-1085040Plan
Computrols CBAS 18.0.0 has Default Credentials.
CriticalCVSS 9.8No exploitEPSS 2%computrols · computrols building automation softwareMay 23, 2019
- CVE-2019-1085436Monitor
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
HighCVSS 8.8No exploitEPSS 3%computrols · computrols building automation softwareMay 23, 2019
- CVE-2019-1084736Monitor
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
HighCVSS 8.8Proof of conceptEPSS 2%computrols · computrols building automation softwareMay 24, 2019
- CVE-2019-1085236Monitor
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start
HighCVSS 8.8No exploitEPSS 2%computrols · computrols building automation softwareMay 23, 2019
- CVE-2019-1084933Monitor
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
HighCVSS 7.5Proof of conceptEPSS 9%computrols · computrols building automation softwareMay 23, 2019
- CVE-2019-1085332Monitor
Computrols CBAS 18.0.0 allows Authentication Bypass.
HighCVSS 8.1No exploitEPSS 2%computrols · computrols building automation softwareMay 23, 2019
- CVE-2019-1085530Monitor
Computrols CBAS 18.0.0 mishandles password hashes.
HighCVSS 7.5No exploitEPSS 1%computrols · computrols building automation softwareMay 23, 2019
- CVE-2019-1085126Monitor
Computrols CBAS 18.0.0 has hard-coded encryption keys.
MediumCVSS 6.5No exploitEPSS 1%computrols · computrols building automation softwareMay 23, 2019
- CVE-2019-1084625Monitor
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via t
MediumCVSS 6.1Proof of conceptEPSS 5%computrols · computrols building automation systemMay 23, 2019
- CVE-2019-1084824Monitor
Computrols CBAS 18.0.0 allows Username Enumeration.
MediumCVSS 5.3Proof of conceptEPSS 8%computrols · computrols building automation softwareMay 24, 2019