Записи computrols
10 опубликованных записей вендора computrols.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-798 Use of Hard-coded Credentials2
- CWE-326 Inadequate Encryption Strength1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-10850Эксплойта нет | Computrols CBAS 18.0.0 has Default Credentials.computrols · computrols building automation software · CWE-798 | Критическая9,8 | — | 1,9 % | 23 мая 2019 г. |
36Наблюдать | CVE-2019-10854Эксплойта нет | Computrols CBAS 18.0.0 allows Authenticated Command Injection.computrols · computrols building automation software · CWE-77 | Высокая8,8 | — | 3,0 % | 23 мая 2019 г. |
36Наблюдать | CVE-2019-10847Proof of concept | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.computrols · computrols building automation software · CWE-352 | Высокая8,8 | — | 2,4 % | 24 мая 2019 г. |
36Наблюдать | CVE-2019-10852Эксплойта нет | Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=startcomputrols · computrols building automation software · CWE-89 | Высокая8,8 | — | 1,8 % | 23 мая 2019 г. |
33Наблюдать | CVE-2019-10849Proof of concept | Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.computrols · computrols building automation software · CWE-862 | Высокая7,5 | — | 9,0 % | 23 мая 2019 г. |
32Наблюдать | CVE-2019-10853Эксплойта нет | Computrols CBAS 18.0.0 allows Authentication Bypass.computrols · computrols building automation software | Высокая8,1 | — | 1,7 % | 23 мая 2019 г. |
30Наблюдать | CVE-2019-10855Эксплойта нет | Computrols CBAS 18.0.0 mishandles password hashes.computrols · computrols building automation software · CWE-326 | Высокая7,5 | — | 1,0 % | 23 мая 2019 г. |
26Наблюдать | CVE-2019-10851Эксплойта нет | Computrols CBAS 18.0.0 has hard-coded encryption keys.computrols · computrols building automation software · CWE-798 | Средняя6,5 | — | 0,7 % | 23 мая 2019 г. |
25Наблюдать | CVE-2019-10846Proof of concept | Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via tcomputrols · computrols building automation system · CWE-79 | Средняя6,1 | — | 4,7 % | 23 мая 2019 г. |
24Наблюдать | CVE-2019-10848Proof of concept | Computrols CBAS 18.0.0 allows Username Enumeration.computrols · computrols building automation software · CWE-203 | Средняя5,3 | — | 8,5 % | 24 мая 2019 г. |
- CVE-2019-1085040В плане
Computrols CBAS 18.0.0 has Default Credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %computrols · computrols building automation software23 мая 2019 г.
- CVE-2019-1085436Наблюдать
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %computrols · computrols building automation software23 мая 2019 г.
- CVE-2019-1084736Наблюдать
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %computrols · computrols building automation software24 мая 2019 г.
- CVE-2019-1085236Наблюдать
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %computrols · computrols building automation software23 мая 2019 г.
- CVE-2019-1084933Наблюдать
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %computrols · computrols building automation software23 мая 2019 г.
- CVE-2019-1085332Наблюдать
Computrols CBAS 18.0.0 allows Authentication Bypass.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %computrols · computrols building automation software23 мая 2019 г.
- CVE-2019-1085530Наблюдать
Computrols CBAS 18.0.0 mishandles password hashes.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %computrols · computrols building automation software23 мая 2019 г.
- CVE-2019-1085126Наблюдать
Computrols CBAS 18.0.0 has hard-coded encryption keys.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %computrols · computrols building automation software23 мая 2019 г.
- CVE-2019-1084625Наблюдать
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via t
СредняяCVSS 6,1Proof of conceptEPSS 5 %computrols · computrols building automation system23 мая 2019 г.
- CVE-2019-1084824Наблюдать
Computrols CBAS 18.0.0 allows Username Enumeration.
СредняяCVSS 5,3Proof of conceptEPSS 8 %computrols · computrols building automation software24 мая 2019 г.