Skip to content
Noroxi

secure elements records

14 published records for vendor secure elements.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      14 records
      • CVE-2006-2715
        31Monitor

        The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote att

        HighCVSS 7.5No exploitEPSS 2%

        secure elements · c5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2716
        31Monitor

        Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain a

        HighCVSS 7.5No exploitEPSS 2%

        secure elements · c5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2709
        21Monitor

        Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1)

        MediumCVSS 5.0No exploitEPSS 4%

        secure elements · class 5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2712
        21Monitor

        Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote

        MediumCVSS 5.0No exploitEPSS 3%

        secure elements · class 5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2708
        21Monitor

        Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · class 5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2706
        21Monitor

        Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start"

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · class 5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2705
        21Monitor

        Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large n

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · c5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2704
        21Monitor

        Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read se

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · c5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2711
        21Monitor

        Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key f

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · class 5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2713
        21Monitor

        Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEI

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · c5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2710
        21Monitor

        Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers w

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · class 5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2714
        21Monitor

        Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attacker

        MediumCVSS 5.0No exploitEPSS 2%

        secure elements · c5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2707
        20Monitor

        Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could al

        MediumCVSS 5.0No exploitEPSS 1%

        secure elements · class 5 enterprise vulnerability managementMay 31, 2006

      • CVE-2006-2717
        17Monitor

        Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overw

        MediumCVSS 4.0No exploitEPSS 2%

        secure elements · c5 enterprise vulnerability managementMay 31, 2006