apsystems kayıtları
apsystems üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-284 Improper Access Control1
- CWE-345 Insufficient Verification of Data Authenticity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2023-28343Kavram kanıtı | OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezapsystems · energy communication unit firmware · CWE-78 | Kritik9,8 | — | %84,8 | 14 Mar 2023 |
62Bu hafta | CVE-2022-45699Kavram kanıtı | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrapsystems · ecu-r firmware · CWE-78 | Kritik9,8 | — | %76,6 | 9 Şub 2023 |
35İzleyin | CVE-2022-44037İstismar yok | An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allowapsystems · ecu-c firmware · CWE-284 | Yüksek8,8 | — | %0,6 | 29 Kas 2022 |
28İzleyin | CVE-2023-31502İstismar yok | Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/manaapsystems · alternergy power control software · CWE-345 | Yüksek7,2 | — | %0,7 | 11 May 2023 |
- CVE-2023-2834364Bu hafta
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timez
KritikCVSS 9,8Kavram kanıtıEPSS %85apsystems · energy communication unit firmware14 Mar 2023
- CVE-2022-4569962Bu hafta
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitr
KritikCVSS 9,8Kavram kanıtıEPSS %77apsystems · ecu-r firmware9 Şub 2023
- CVE-2022-4403735İzleyin
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allow
YüksekCVSS 8,8İstismar yokEPSS %1apsystems · ecu-c firmware29 Kas 2022
- CVE-2023-3150228İzleyin
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/mana
YüksekCVSS 7,2İstismar yokEPSS %1apsystems · alternergy power control software11 May 2023