Записи ecobee
4 опубликованных записей вендора ecobee.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-27952Эксплойта нет | Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device.ecobee · ecobee3 lite firmware · CWE-798 | Критическая9,8 | — | 1,1 % | 3 авг. 2021 г. |
32Наблюдать | CVE-2021-27954Эксплойта нет | A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wirelecobee · ecobee3 lite firmware · CWE-787 | Высокая8,2 | — | 0,9 % | 3 авг. 2021 г. |
31Наблюдать | CVE-2021-27953Эксплойта нет | A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process.ecobee · ecobee3 lite firmware · CWE-476 | Высокая7,5 | — | 1,7 % | 3 авг. 2021 г. |
30Наблюдать | CVE-2018-6402Эксплойта нет | Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if theecobee · ecobee4 firmware · CWE-327 | Высокая7,5 | — | 0,2 % | 14 апр. 2020 г. |
- CVE-2021-2795239Наблюдать
Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ecobee · ecobee3 lite firmware3 авг. 2021 г.
- CVE-2021-2795432Наблюдать
A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wirel
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %ecobee · ecobee3 lite firmware3 авг. 2021 г.
- CVE-2021-2795331Наблюдать
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ecobee · ecobee3 lite firmware3 авг. 2021 г.
- CVE-2018-640230Наблюдать
Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if the
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ecobee · ecobee4 firmware14 апр. 2020 г.