Записи apsystems
4 опубликованных записей вендора apsystems.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-284 Improper Access Control1
- CWE-345 Insufficient Verification of Data Authenticity1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2023-28343Proof of concept | OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezapsystems · energy communication unit firmware · CWE-78 | Критическая9,8 | — | 84,8 % | 14 мар. 2023 г. |
62На этой неделе | CVE-2022-45699Proof of concept | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrapsystems · ecu-r firmware · CWE-78 | Критическая9,8 | — | 76,6 % | 9 февр. 2023 г. |
35Наблюдать | CVE-2022-44037Эксплойта нет | An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allowapsystems · ecu-c firmware · CWE-284 | Высокая8,8 | — | 0,6 % | 29 нояб. 2022 г. |
28Наблюдать | CVE-2023-31502Эксплойта нет | Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/manaapsystems · alternergy power control software · CWE-345 | Высокая7,2 | — | 0,7 % | 11 мая 2023 г. |
- CVE-2023-2834364На этой неделе
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timez
КритическаяCVSS 9,8Proof of conceptEPSS 85 %apsystems · energy communication unit firmware14 мар. 2023 г.
- CVE-2022-4569962На этой неделе
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitr
КритическаяCVSS 9,8Proof of conceptEPSS 77 %apsystems · ecu-r firmware9 февр. 2023 г.
- CVE-2022-4403735Наблюдать
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allow
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apsystems · ecu-c firmware29 нояб. 2022 г.
- CVE-2023-3150228Наблюдать
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/mana
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %apsystems · alternergy power control software11 мая 2023 г.