Skip to content
Noroxi

Janitza records

9 published records for vendor janitza.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easie

    CriticalCVSS 10.0No exploitEPSS 3%

    janitza · umg 508Oct 28, 2015

  • In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password

    HighCVSS 8.8No exploitEPSS 0%

    janitza · gridvisMar 26, 2024

  • CVE-2015-3968
    31Monitor

    The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for remote attackers to rea

    HighCVSS 7.5No exploitEPSS 2%

    janitza · umg 508Oct 28, 2015

  • CVE-2015-3971
    30Monitor

    The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to rea

    HighCVSS 7.5No exploitEPSS 2%

    janitza · umg 508Oct 28, 2015

  • In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functi

    HighCVSS 7.2No exploitEPSS 1%

    janitza · gridvisMar 26, 2024

  • CVE-2015-3967
    27Monitor

    Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the aut

    MediumCVSS 6.8No exploitEPSS 1%

    janitza · umg 508Oct 28, 2015

  • CVE-2015-3973
    20Monitor

    Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote attackers to determine

    MediumCVSS 5.0No exploitEPSS 1%

    janitza · umg 508Oct 28, 2015

  • CVE-2015-3969
    20Monitor

    Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to U

    MediumCVSS 5.0No exploitEPSS 1%

    janitza · umg 508Oct 28, 2015

  • CVE-2015-3970
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote att

    MediumCVSS 4.3No exploitEPSS 1%

    janitza · umg 508Oct 28, 2015