Записи secure elements
14 опубликованных записей вендора secure elements.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2006-2715Эксплойта нет | The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attsecure elements · c5 enterprise vulnerability management | Высокая7,5 | — | 2,2 % | 31 мая 2006 г. |
31Наблюдать | CVE-2006-2716Эксплойта нет | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain asecure elements · c5 enterprise vulnerability management | Высокая7,5 | — | 2,2 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2709Эксплойта нет | Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) secure elements · class 5 enterprise vulnerability management | Средняя5,0 | — | 3,7 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2712Эксплойта нет | Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remotesecure elements · class 5 enterprise vulnerability management | Средняя5,0 | — | 2,6 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2708Эксплойта нет | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size secure elements · class 5 enterprise vulnerability management | Средняя5,0 | — | 2,4 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2706Эксплойта нет | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start"secure elements · class 5 enterprise vulnerability management | Средняя5,0 | — | 2,2 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2705Эксплойта нет | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large nsecure elements · c5 enterprise vulnerability management | Средняя5,0 | — | 2,2 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2704Эксплойта нет | Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sesecure elements · c5 enterprise vulnerability management | Средняя5,0 | — | 2,1 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2711Эксплойта нет | Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key fsecure elements · class 5 enterprise vulnerability management | Средняя5,0 | — | 1,9 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2713Эксплойта нет | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEIsecure elements · c5 enterprise vulnerability management | Средняя5,0 | — | 1,9 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2710Эксплойта нет | Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers wsecure elements · class 5 enterprise vulnerability management | Средняя5,0 | — | 1,9 % | 31 мая 2006 г. |
21Наблюдать | CVE-2006-2714Эксплойта нет | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackersecure elements · c5 enterprise vulnerability management | Средняя5,0 | — | 1,9 % | 31 мая 2006 г. |
20Наблюдать | CVE-2006-2707Эксплойта нет | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could alsecure elements · class 5 enterprise vulnerability management | Средняя5,0 | — | 1,1 % | 31 мая 2006 г. |
17Наблюдать | CVE-2006-2717Эксплойта нет | Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overwsecure elements · c5 enterprise vulnerability management | Средняя4,0 | — | 1,9 % | 31 мая 2006 г. |
- CVE-2006-271531Наблюдать
The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote att
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %secure elements · c5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-271631Наблюдать
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %secure elements · c5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-270921Наблюдать
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1)
СредняяCVSS 5,0Эксплойта нетEPSS 4 %secure elements · class 5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-271221Наблюдать
Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote
СредняяCVSS 5,0Эксплойта нетEPSS 3 %secure elements · class 5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-270821Наблюдать
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · class 5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-270621Наблюдать
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start"
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · class 5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-270521Наблюдать
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large n
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · c5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-270421Наблюдать
Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read se
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · c5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-271121Наблюдать
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key f
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · class 5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-271321Наблюдать
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEI
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · c5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-271021Наблюдать
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers w
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · class 5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-271421Наблюдать
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attacker
СредняяCVSS 5,0Эксплойта нетEPSS 2 %secure elements · c5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-270720Наблюдать
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could al
СредняяCVSS 5,0Эксплойта нетEPSS 1 %secure elements · class 5 enterprise vulnerability management31 мая 2006 г.
- CVE-2006-271717Наблюдать
Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overw
СредняяCVSS 4,0Эксплойта нетEPSS 2 %secure elements · c5 enterprise vulnerability management31 мая 2006 г.