Записи CoolKIt
4 опубликованных записей вендора coolkit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-305 Authentication Bypass by Primary Weakness1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-522 Insufficiently Protected Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2024-7205Эксплойта нет | sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary usercoolkit · ewelink cloud service · CWE-201 | Критическая9,4 | — | 0,5 % | 31 июл. 2024 г. |
30Наблюдать | CVE-2023-6998Эксплойта нет | Lockscreen bypass in eWeLink Appcoolkit · ewelink · CWE-305 | Высокая7,7 | — | 0,2 % | 30 дек. 2023 г. |
18Наблюдать | CVE-2020-12702Proof of concept | Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 coolkit · ewelink · CWE-327 | Средняя4,6 | — | 0,3 % | 24 февр. 2021 г. |
18Наблюдать | CVE-2021-27941Эксплойта нет | Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2coolkit · ewelink · CWE-522 | Средняя4,6 | — | 0,2 % | 6 мая 2021 г. |
- CVE-2024-720537Наблюдать
sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %coolkit · ewelink cloud service31 июл. 2024 г.
- CVE-2023-699830Наблюдать
Lockscreen bypass in eWeLink App
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %coolkit · ewelink30 дек. 2023 г.
- CVE-2020-1270218Наблюдать
Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1
СредняяCVSS 4,6Proof of conceptEPSS 0 %coolkit · ewelink24 февр. 2021 г.
- CVE-2021-2794118Наблюдать
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2
СредняяCVSS 4,6Эксплойта нетEPSS 0 %coolkit · ewelink6 мая 2021 г.