edgexfoundry records
3 published records for vendor edgexfoundry.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-284 Improper Access Control1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2021-32753No exploit | Weak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-edgexfoundry · edgex foundry · CWE-284 | Medium6.5 | — | 0.8% | Jul 9, 2021 |
22Monitor | CVE-2021-41278Proof of concept | Broken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via unspecified vectorsedgexfoundry · app service configurable · CWE-327 | Medium5.7 | — | 0.3% | Nov 18, 2021 |
17Monitor | CVE-2022-31066No exploit | Configuration API in EdgeXFoundry exposes message bus credentials to local unauthenticated usersedgexfoundry · edgex foundry · CWE-200 | Medium4.4 | — | 0.3% | Jun 14, 2022 |
- CVE-2021-3275326Monitor
Weak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-
MediumCVSS 6.5No exploitEPSS 1%edgexfoundry · edgex foundryJul 9, 2021
- CVE-2021-4127822Monitor
Broken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via unspecified vectors
MediumCVSS 5.7Proof of conceptEPSS 0%edgexfoundry · app service configurableNov 18, 2021
- CVE-2022-3106617Monitor
Configuration API in EdgeXFoundry exposes message bus credentials to local unauthenticated users
MediumCVSS 4.4No exploitEPSS 0%edgexfoundry · edgex foundryJun 14, 2022