secure elements records
14 published records for vendor secure elements.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-2715No exploit | The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attsecure elements · c5 enterprise vulnerability management | High7.5 | — | 2.2% | May 31, 2006 |
31Monitor | CVE-2006-2716No exploit | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain asecure elements · c5 enterprise vulnerability management | High7.5 | — | 2.2% | May 31, 2006 |
21Monitor | CVE-2006-2709No exploit | Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) secure elements · class 5 enterprise vulnerability management | Medium5.0 | — | 3.7% | May 31, 2006 |
21Monitor | CVE-2006-2712No exploit | Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remotesecure elements · class 5 enterprise vulnerability management | Medium5.0 | — | 2.6% | May 31, 2006 |
21Monitor | CVE-2006-2708No exploit | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size secure elements · class 5 enterprise vulnerability management | Medium5.0 | — | 2.4% | May 31, 2006 |
21Monitor | CVE-2006-2706No exploit | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start"secure elements · class 5 enterprise vulnerability management | Medium5.0 | — | 2.2% | May 31, 2006 |
21Monitor | CVE-2006-2705No exploit | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large nsecure elements · c5 enterprise vulnerability management | Medium5.0 | — | 2.2% | May 31, 2006 |
21Monitor | CVE-2006-2704No exploit | Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sesecure elements · c5 enterprise vulnerability management | Medium5.0 | — | 2.1% | May 31, 2006 |
21Monitor | CVE-2006-2711No exploit | Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key fsecure elements · class 5 enterprise vulnerability management | Medium5.0 | — | 1.9% | May 31, 2006 |
21Monitor | CVE-2006-2713No exploit | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEIsecure elements · c5 enterprise vulnerability management | Medium5.0 | — | 1.9% | May 31, 2006 |
21Monitor | CVE-2006-2710No exploit | Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers wsecure elements · class 5 enterprise vulnerability management | Medium5.0 | — | 1.9% | May 31, 2006 |
21Monitor | CVE-2006-2714No exploit | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackersecure elements · c5 enterprise vulnerability management | Medium5.0 | — | 1.9% | May 31, 2006 |
20Monitor | CVE-2006-2707No exploit | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could alsecure elements · class 5 enterprise vulnerability management | Medium5.0 | — | 1.1% | May 31, 2006 |
17Monitor | CVE-2006-2717No exploit | Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overwsecure elements · c5 enterprise vulnerability management | Medium4.0 | — | 1.9% | May 31, 2006 |
- CVE-2006-271531Monitor
The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote att
HighCVSS 7.5No exploitEPSS 2%secure elements · c5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-271631Monitor
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain a
HighCVSS 7.5No exploitEPSS 2%secure elements · c5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-270921Monitor
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1)
MediumCVSS 5.0No exploitEPSS 4%secure elements · class 5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-271221Monitor
Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote
MediumCVSS 5.0No exploitEPSS 3%secure elements · class 5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-270821Monitor
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size
MediumCVSS 5.0No exploitEPSS 2%secure elements · class 5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-270621Monitor
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start"
MediumCVSS 5.0No exploitEPSS 2%secure elements · class 5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-270521Monitor
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large n
MediumCVSS 5.0No exploitEPSS 2%secure elements · c5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-270421Monitor
Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read se
MediumCVSS 5.0No exploitEPSS 2%secure elements · c5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-271121Monitor
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key f
MediumCVSS 5.0No exploitEPSS 2%secure elements · class 5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-271321Monitor
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEI
MediumCVSS 5.0No exploitEPSS 2%secure elements · c5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-271021Monitor
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers w
MediumCVSS 5.0No exploitEPSS 2%secure elements · class 5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-271421Monitor
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attacker
MediumCVSS 5.0No exploitEPSS 2%secure elements · c5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-270720Monitor
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could al
MediumCVSS 5.0No exploitEPSS 1%secure elements · class 5 enterprise vulnerability managementMay 31, 2006
- CVE-2006-271717Monitor
Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overw
MediumCVSS 4.0No exploitEPSS 2%secure elements · c5 enterprise vulnerability managementMay 31, 2006