cs-technologies records
9 published records for vendor cs-technologies.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-284 Improper Access Control2
- CWE-1392 Use of Default Credentials1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-29844No exploit | Default credentials on web interface of Evolution Controller Versions allows attackers to login and perform administrative functionscs-technologies · evolution · CWE-1392 | Critical9.8 | — | 0.6% | Apr 14, 2024 |
39Monitor | CVE-2024-29836No exploit | Broken Authentication on USER_CHANGE in Evolution Controller allows unauthenticated account creation and takeovercs-technologies · evolution · CWE-284 | Critical9.8 | — | 0.6% | Apr 14, 2024 |
35Monitor | CVE-2024-29837No exploit | Poor session management in Evolution Controller allows administrator functionality for unauthenticated connectionscs-technologies · evolution · CWE-284 | High8.8 | — | 0.5% | Apr 14, 2024 |
30Monitor | CVE-2024-29838No exploit | Unsanitised variable on DAL_ADD in Evolution Controller causes application level denial of service and crashcs-technologies · evolution · CWE-20 | High7.5 | — | 0.5% | Apr 14, 2024 |
30Monitor | CVE-2024-29840No exploit | Broken Access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve PIN field valuescs-technologies · evolution · CWE-200 | High7.5 | — | 0.5% | Apr 14, 2024 |
30Monitor | CVE-2024-29842No exploit | Broken Access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve ABACARD valuescs-technologies · evolution · CWE-200 | High7.5 | — | 0.5% | Apr 14, 2024 |
30Monitor | CVE-2024-29843No exploit | Broken Access control on MOBILE_GET_USERS_LIST in Evolution Controller allows unauthenticated user enumerationcs-technologies · evolution · CWE-200 | High7.5 | — | 0.5% | Apr 14, 2024 |
30Monitor | CVE-2024-29841No exploit | Broken Access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve keys valuescs-technologies · evolution · CWE-200 | High7.5 | — | 0.5% | Apr 14, 2024 |
30Monitor | CVE-2024-29839No exploit | Broken Access control on DESKTOP_EDIT_USER_GET_CARD in Evolution Controller allows unauthenticated attackers to retrieve card data values.cs-technologies · evolution · CWE-200 | High7.5 | — | 0.5% | Apr 14, 2024 |
- CVE-2024-2984439Monitor
Default credentials on web interface of Evolution Controller Versions allows attackers to login and perform administrative functions
CriticalCVSS 9.8No exploitEPSS 1%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2983639Monitor
Broken Authentication on USER_CHANGE in Evolution Controller allows unauthenticated account creation and takeover
CriticalCVSS 9.8No exploitEPSS 1%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2983735Monitor
Poor session management in Evolution Controller allows administrator functionality for unauthenticated connections
HighCVSS 8.8No exploitEPSS 1%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2983830Monitor
Unsanitised variable on DAL_ADD in Evolution Controller causes application level denial of service and crash
HighCVSS 7.5No exploitEPSS 1%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2984030Monitor
Broken Access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve PIN field values
HighCVSS 7.5No exploitEPSS 0%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2984230Monitor
Broken Access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve ABACARD values
HighCVSS 7.5No exploitEPSS 0%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2984330Monitor
Broken Access control on MOBILE_GET_USERS_LIST in Evolution Controller allows unauthenticated user enumeration
HighCVSS 7.5No exploitEPSS 0%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2984130Monitor
Broken Access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve keys values
HighCVSS 7.5No exploitEPSS 0%cs-technologies · evolutionApr 14, 2024
- CVE-2024-2983930Monitor
Broken Access control on DESKTOP_EDIT_USER_GET_CARD in Evolution Controller allows unauthenticated attackers to retrieve card data values.
HighCVSS 7.5No exploitEPSS 0%cs-technologies · evolutionApr 14, 2024