easyio records
3 published records for vendor easyio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-255 Credentials Management Errors1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2015-3974No exploit | EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/Easyeasyio · easyio-30p-sf firmware · CWE-255 | Critical9.0 | — | 1.9% | Sep 27, 2015 |
31Monitor | CVE-2018-15819No exploit | EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.easyio · easyio 30p firmware · CWE-287 | High7.5 | — | 1.8% | Mar 2, 2020 |
24Monitor | CVE-2018-15820No exploit | EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.easyio · easyio 30p firmware · CWE-79 | Medium6.1 | — | 0.9% | Mar 2, 2020 |
- CVE-2015-397437Monitor
EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/Easy
CriticalCVSS 9.0No exploitEPSS 2%easyio · easyio-30p-sf firmwareSep 27, 2015
- CVE-2018-1581931Monitor
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
HighCVSS 7.5No exploitEPSS 2%easyio · easyio 30p firmwareMar 2, 2020
- CVE-2018-1582024Monitor
EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
MediumCVSS 6.1No exploitEPSS 1%easyio · easyio 30p firmwareMar 2, 2020