Записи mersive
7 опубликованных записей вендора mersive.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-307 Improper Restriction of Excessive Authentication Attempts2
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-12945Proof of concept | Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers tomersive · solstice firmware · CWE-78 | Высокая8,8 | — | 17,5 % | 27 нояб. 2019 г. |
31Наблюдать | CVE-2020-27523Эксплойта нет | Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_namersive · solstice pod firmware · CWE-134 | Высокая7,5 | — | 2,0 % | 11 нояб. 2020 г. |
30Наблюдать | CVE-2020-35587Эксплойта нет | In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled.mersive · solstice firmware · CWE-311 | Высокая7,5 | — | 1,5 % | 23 дек. 2020 г. |
30Наблюдать | CVE-2020-35585Эксплойта нет | In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Conmersive · solstice pod firmware · CWE-307 | Высокая7,5 | — | 1,4 % | 23 дек. 2020 г. |
30Наблюдать | CVE-2020-35586Эксплойта нет | In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/inmersive · solstice pod firmware · CWE-307 | Высокая7,5 | — | 1,4 % | 23 дек. 2020 г. |
27Наблюдать | CVE-2025-66573Эксплойта нет | Solstice Pod API Session Key Extraction via API Endpointmersive · solstice pod firmware · CWE-319 | Средняя6,9 | — | 0,3 % | 4 дек. 2025 г. |
23Наблюдать | CVE-2020-35584Эксплойта нет | In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature.mersive · solstice pod firmware · CWE-319 | Средняя5,9 | — | 0,8 % | 23 дек. 2020 г. |
- CVE-2017-1294540В плане
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %mersive · solstice firmware27 нояб. 2019 г.
- CVE-2020-2752331Наблюдать
Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_na
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mersive · solstice pod firmware11 нояб. 2020 г.
- CVE-2020-3558730Наблюдать
In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mersive · solstice firmware23 дек. 2020 г.
- CVE-2020-3558530Наблюдать
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Con
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mersive · solstice pod firmware23 дек. 2020 г.
- CVE-2020-3558630Наблюдать
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/in
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mersive · solstice pod firmware23 дек. 2020 г.
- CVE-2025-6657327Наблюдать
Solstice Pod API Session Key Extraction via API Endpoint
СредняяCVSS 6,9Эксплойта нетEPSS 0 %mersive · solstice pod firmware4 дек. 2025 г.
- CVE-2020-3558423Наблюдать
In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %mersive · solstice pod firmware23 дек. 2020 г.