elenos records
8 published records for vendor elenos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-204 Observable Response Discrepancy1
- CWE-281 Improper Preservation of Permissions1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-613 Insufficient Session Expiration1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-34671No exploit | Improper Access Control leads to privilege escalation affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's roelenos · etg150 fm firmware | High8.8 | — | 0.9% | Jun 23, 2023 |
35Monitor | CVE-2023-34672No exploit | Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting uelenos · etg150 firmware · CWE-281 | High8.8 | — | 0.7% | Jun 23, 2023 |
30Monitor | CVE-2023-37832No exploit | A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unelenos · etg150 firmware · CWE-307 | High7.5 | — | 0.5% | Oct 31, 2023 |
26Monitor | CVE-2023-34673No exploit | Elenos ETG150 FM transmitter running on version 3.12 was discovered to be leaking SMTP credentials and other sensitive information by exploielenos · etg150 firmware | Medium6.5 | — | 0.7% | Jun 23, 2023 |
26Monitor | CVE-2023-45396No exploit | An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version elenos · etg150 firmware · CWE-639 | Medium6.5 | — | 0.4% | Oct 11, 2023 |
21Monitor | CVE-2023-37831No exploit | An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentelenos · etg150 firmware · CWE-204 | Medium5.3 | — | 0.5% | Oct 31, 2023 |
21Monitor | CVE-2023-39695No exploit | Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and delenos · etg150 firmware · CWE-613 | Medium5.3 | — | 0.4% | Oct 31, 2023 |
10Monitor | CVE-2023-37833No exploit | Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed elenos · etg150 firmware · CWE-20 | Low2.7 | — | 0.4% | Oct 31, 2023 |
- CVE-2023-3467135Monitor
Improper Access Control leads to privilege escalation affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's ro
HighCVSS 8.8No exploitEPSS 1%elenos · etg150 fm firmwareJun 23, 2023
- CVE-2023-3467235Monitor
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting u
HighCVSS 8.8No exploitEPSS 1%elenos · etg150 firmwareJun 23, 2023
- CVE-2023-3783230Monitor
A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other un
HighCVSS 7.5No exploitEPSS 1%elenos · etg150 firmwareOct 31, 2023
- CVE-2023-3467326Monitor
Elenos ETG150 FM transmitter running on version 3.12 was discovered to be leaking SMTP credentials and other sensitive information by exploi
MediumCVSS 6.5No exploitEPSS 1%elenos · etg150 firmwareJun 23, 2023
- CVE-2023-4539626Monitor
An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version
MediumCVSS 6.5No exploitEPSS 0%elenos · etg150 firmwareOct 11, 2023
- CVE-2023-3783121Monitor
An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credent
MediumCVSS 5.3No exploitEPSS 0%elenos · etg150 firmwareOct 31, 2023
- CVE-2023-3969521Monitor
Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and d
MediumCVSS 5.3No exploitEPSS 0%elenos · etg150 firmwareOct 31, 2023
- CVE-2023-3783310Monitor
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed
LowCVSS 2.7No exploitEPSS 0%elenos · etg150 firmwareOct 31, 2023