eic records
5 published records for vendor eic.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-22859No exploit | EIC e-document system - SQL Injectioneic · e-document system · CWE-89 | Critical9.8 | — | 3.8% | Mar 17, 2021 |
40Plan | CVE-2021-22860No exploit | EIC e-document system - Broken Authenticationeic · e-document system · CWE-287 | Critical9.8 | — | 2.6% | Mar 17, 2021 |
39Monitor | CVE-2019-11232No exploit | EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_Neic · biyan · CWE-287 | Critical9.8 | — | 1.5% | Jun 19, 2019 |
30Monitor | CVE-2019-11233No exploit | EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element eic · biyan · CWE-200 | High7.5 | — | 1.5% | Jun 19, 2019 |
21Monitor | CVE-2021-34683No exploit | An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0.eic · e-document system | Medium5.3 | — | 1.1% | Jun 16, 2021 |
- CVE-2021-2285940Plan
EIC e-document system - SQL Injection
CriticalCVSS 9.8No exploitEPSS 4%eic · e-document systemMar 17, 2021
- CVE-2021-2286040Plan
EIC e-document system - Broken Authentication
CriticalCVSS 9.8No exploitEPSS 3%eic · e-document systemMar 17, 2021
- CVE-2019-1123239Monitor
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_N
CriticalCVSS 9.8No exploitEPSS 2%eic · biyanJun 19, 2019
- CVE-2019-1123330Monitor
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element
HighCVSS 7.5No exploitEPSS 2%eic · biyanJun 19, 2019
- CVE-2021-3468321Monitor
An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0.
MediumCVSS 5.3No exploitEPSS 1%eic · e-document systemJun 16, 2021