Записи eWON
6 опубликованных записей вендора ewon.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2015-7926Эксплойта нет | eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sewon · ewon firmware · CWE-200 | Критическая9,9 | — | 3,4 % | 23 дек. 2015 г. |
36Наблюдать | CVE-2015-7924Эксплойта нет | eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes ewon · ewon firmware | Высокая8,8 | — | 2,1 % | 23 дек. 2015 г. |
35Наблюдать | CVE-2015-7928Эксплойта нет | eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote atewon · ewon firmware · CWE-200 | Высокая8,5 | — | 3,2 % | 23 дек. 2015 г. |
32Наблюдать | CVE-2015-7925Эксплойта нет | Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authenticewon · ewon firmware · CWE-352 | Высокая8,0 | — | 1,2 % | 23 дек. 2015 г. |
25Наблюдать | CVE-2015-7927Эксплойта нет | Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject arbitrary web scriptewon · ewon firmware · CWE-79 | Средняя6,1 | — | 2,0 % | 23 дек. 2015 г. |
18Наблюдать | CVE-2015-7929Эксплойта нет | eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive informatiewon · ewon firmware · CWE-200 | Средняя4,3 | — | 2,6 % | 23 дек. 2015 г. |
- CVE-2015-792640В плане
eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain s
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %ewon · ewon firmware23 дек. 2015 г.
- CVE-2015-792436Наблюдать
eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %ewon · ewon firmware23 дек. 2015 г.
- CVE-2015-792835Наблюдать
eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote at
ВысокаяCVSS 8,5Эксплойта нетEPSS 3 %ewon · ewon firmware23 дек. 2015 г.
- CVE-2015-792532Наблюдать
Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentic
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %ewon · ewon firmware23 дек. 2015 г.
- CVE-2015-792725Наблюдать
Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject arbitrary web script
СредняяCVSS 6,1Эксплойта нетEPSS 2 %ewon · ewon firmware23 дек. 2015 г.
- CVE-2015-792918Наблюдать
eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive informati
СредняяCVSS 4,3Эксплойта нетEPSS 3 %ewon · ewon firmware23 дек. 2015 г.