Janitza records
9 published records for vendor janitza.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-254 7PK - Security Features2
- CWE-255 Credentials Management Errors1
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2015-3972No exploit | The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easiejanitza · umg 508 · CWE-254 | Critical10.0 | — | 2.9% | Oct 28, 2015 |
35Monitor | CVE-2023-50894No exploit | In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password janitza · gridvis · CWE-200 | High8.8 | — | 0.4% | Mar 26, 2024 |
31Monitor | CVE-2015-3968No exploit | The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for remote attackers to reajanitza · umg 508 · CWE-255 | High7.5 | — | 2.3% | Oct 28, 2015 |
30Monitor | CVE-2015-3971No exploit | The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to reajanitza · umg 508 · CWE-284 | High7.5 | — | 1.6% | Oct 28, 2015 |
28Monitor | CVE-2023-50895No exploit | In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functijanitza · gridvis | High7.2 | — | 0.7% | Mar 26, 2024 |
27Monitor | CVE-2015-3967No exploit | Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the autjanitza · umg 508 · CWE-352 | Medium6.8 | — | 0.6% | Oct 28, 2015 |
20Monitor | CVE-2015-3973No exploit | Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote attackers to determine janitza · umg 508 · CWE-254 | Medium5.0 | — | 1.5% | Oct 28, 2015 |
20Monitor | CVE-2015-3969No exploit | Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to Ujanitza · umg 508 · CWE-200 | Medium5.0 | — | 1.4% | Oct 28, 2015 |
17Monitor | CVE-2015-3970No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attjanitza · umg 508 · CWE-79 | Medium4.3 | — | 1.1% | Oct 28, 2015 |
- CVE-2015-397241Plan
The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easie
CriticalCVSS 10.0No exploitEPSS 3%janitza · umg 508Oct 28, 2015
- CVE-2023-5089435Monitor
In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password
HighCVSS 8.8No exploitEPSS 0%janitza · gridvisMar 26, 2024
- CVE-2015-396831Monitor
The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for remote attackers to rea
HighCVSS 7.5No exploitEPSS 2%janitza · umg 508Oct 28, 2015
- CVE-2015-397130Monitor
The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to rea
HighCVSS 7.5No exploitEPSS 2%janitza · umg 508Oct 28, 2015
- CVE-2023-5089528Monitor
In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functi
HighCVSS 7.2No exploitEPSS 1%janitza · gridvisMar 26, 2024
- CVE-2015-396727Monitor
Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the aut
MediumCVSS 6.8No exploitEPSS 1%janitza · umg 508Oct 28, 2015
- CVE-2015-397320Monitor
Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote attackers to determine
MediumCVSS 5.0No exploitEPSS 1%janitza · umg 508Oct 28, 2015
- CVE-2015-396920Monitor
Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to U
MediumCVSS 5.0No exploitEPSS 1%janitza · umg 508Oct 28, 2015
- CVE-2015-397017Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote att
MediumCVSS 4.3No exploitEPSS 1%janitza · umg 508Oct 28, 2015