infocus records
5 published records for vendor infocus.
Researcher profile
- Entered KEV
- 1 · 20%
- Weaponized
- 1 · 20%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- 1081 days
Recurring classes
- CWE-121 Stack-based Buffer Overflow1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2019-3929Weaponized | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-79 | Critical9.8 | KEV | 99.0% | Apr 30, 2019 |
41Plan | CVE-2019-3930No exploit | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-121 | Critical9.8 | — | 7.0% | Apr 30, 2019 |
41Plan | CVE-2014-8383No exploit | The InFocus IN3128HD projector with firmware 0.26 allows remote attackers to bypass authentication via a direct request to main.html.infocus · in3128hd firmware | Critical10.0 | — | 3.0% | May 18, 2015 |
38Monitor | CVE-2014-8384No exploit | The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modiinfocus · in3128hd firmware | Critical9.4 | — | 3.2% | May 18, 2015 |
30Monitor | CVE-2017-14972No exploit | InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using infocus · mondopad · CWE-287 | High7.5 | — | 1.3% | Oct 9, 2017 |
- CVE-2019-392999Now
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
CriticalCVSS 9.8KEVWeaponizedEPSS 99%crestron · am-100 firmwareApr 30, 2019
- CVE-2019-393041Plan
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
CriticalCVSS 9.8No exploitEPSS 7%crestron · am-100 firmwareApr 30, 2019
- CVE-2014-838341Plan
The InFocus IN3128HD projector with firmware 0.26 allows remote attackers to bypass authentication via a direct request to main.html.
CriticalCVSS 10.0No exploitEPSS 3%infocus · in3128hd firmwareMay 18, 2015
- CVE-2014-838438Monitor
The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modi
CriticalCVSS 9.4No exploitEPSS 3%infocus · in3128hd firmwareMay 18, 2015
- CVE-2017-1497230Monitor
InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using
HighCVSS 7.5No exploitEPSS 1%infocus · mondopadOct 9, 2017