ecos records
11 published records for vendor ecos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-459 Incomplete Cleanup1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-1000020No exploit | SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass.ecos · embedded web servers · CWE-287 | Critical9.8 | — | 2.9% | Jul 17, 2017 |
39Monitor | CVE-2018-12338No exploit | Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information andecos · system management appliance | Critical9.8 | — | 1.5% | Jun 17, 2018 |
39Monitor | CVE-2018-12336No exploit | Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote rooecos · secure boot stick firmware · CWE-200 | Critical9.8 | — | 1.5% | Jun 17, 2018 |
32Monitor | CVE-2018-12330No exploit | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys vecos · secure boot stick firmware | High8.1 | — | 0.8% | Jun 17, 2018 |
32Monitor | CVE-2018-12333No exploit | Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate secuecos · secure boot stick firmware · CWE-345 | High8.1 | — | 0.4% | Jun 17, 2018 |
30Monitor | CVE-2018-12334No exploit | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys vecos · secure boot stick firmware | High7.5 | — | 0.6% | Jun 17, 2018 |
29Monitor | CVE-2018-12331No exploit | Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to ecos · system management appliance · CWE-290 | High7.4 | — | 0.9% | Jun 17, 2018 |
29Monitor | CVE-2018-12335No exploit | Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access anecos · system management appliance · CWE-732 | High7.3 | — | 0.4% | Jun 17, 2018 |
23Monitor | CVE-2018-12329No exploit | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloecos · secure boot stick firmware · CWE-200 | Medium5.9 | — | 0.9% | Jun 17, 2018 |
18Monitor | CVE-2018-12337No exploit | Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confiecos · secure boot stick firmware · CWE-200 | Medium4.6 | — | 0.3% | Jun 17, 2018 |
16Monitor | CVE-2018-12332No exploit | Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keecos · secure boot stick firmware · CWE-459 | Medium4.2 | — | 0.2% | Jun 17, 2018 |
- CVE-2017-100002040Plan
SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass.
CriticalCVSS 9.8No exploitEPSS 3%ecos · embedded web serversJul 17, 2017
- CVE-2018-1233839Monitor
Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and
CriticalCVSS 9.8No exploitEPSS 2%ecos · system management applianceJun 17, 2018
- CVE-2018-1233639Monitor
Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote roo
CriticalCVSS 9.8No exploitEPSS 2%ecos · secure boot stick firmwareJun 17, 2018
- CVE-2018-1233032Monitor
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys v
HighCVSS 8.1No exploitEPSS 1%ecos · secure boot stick firmwareJun 17, 2018
- CVE-2018-1233332Monitor
Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate secu
HighCVSS 8.1No exploitEPSS 0%ecos · secure boot stick firmwareJun 17, 2018
- CVE-2018-1233430Monitor
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys v
HighCVSS 7.5No exploitEPSS 1%ecos · secure boot stick firmwareJun 17, 2018
- CVE-2018-1233129Monitor
Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to
HighCVSS 7.4No exploitEPSS 1%ecos · system management applianceJun 17, 2018
- CVE-2018-1233529Monitor
Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access an
HighCVSS 7.3No exploitEPSS 0%ecos · system management applianceJun 17, 2018
- CVE-2018-1232923Monitor
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via clo
MediumCVSS 5.9No exploitEPSS 1%ecos · secure boot stick firmwareJun 17, 2018
- CVE-2018-1233718Monitor
Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confi
MediumCVSS 4.6No exploitEPSS 0%ecos · secure boot stick firmwareJun 17, 2018
- CVE-2018-1233216Monitor
Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption ke
MediumCVSS 4.2No exploitEPSS 0%ecos · secure boot stick firmwareJun 17, 2018