assaabloy kayıtları
assaabloy üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-326 Inadequate Encryption Strength3
- CWE-287 Improper Authentication1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-668 Exposure of Resource to Wrong Sphere1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-10176İstismar yok | ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.assaabloy · yale wipc-301w firmware · CWE-94 | Kritik9,8 | — | %2,3 | 7 May 2020 |
39İzleyin | CVE-2020-23826İstismar yok | The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API.assaabloy · yale wipc-303w firmware · CWE-78 | Yüksek8,8 | — | %12,6 | 26 Oca 2021 |
39İzleyin | CVE-2023-33367İstismar yok | A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on theassaabloy · control id idsecure · CWE-89 | Kritik9,8 | — | %1,1 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33371İstismar yok | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackersassaabloy · control id idsecure · CWE-798 | Kritik9,8 | — | %0,9 | 2 Ağu 2023 |
39İzleyin | CVE-2023-2043İstismar yok | Control iD RHiD Edit a sql injectionassaabloy · control id rhid · CWE-89 | Kritik9,8 | — | %0,5 | 14 Nis 2023 |
37İzleyin | CVE-2025-49853İstismar yok | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premisesassaabloy · control id idsecure · CWE-89 | Kritik9,3 | — | %0,5 | 24 Haz 2025 |
36İzleyin | CVE-2023-33369İstismar yok | A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure fiassaabloy · control id idsecure · CWE-22 | Kritik9,1 | — | %0,7 | 2 Ağu 2023 |
34İzleyin | CVE-2025-49851İstismar yok | Improper Authentication in ControlID iDSecure On-premisesassaabloy · control id idsecure · CWE-287 | Yüksek8,7 | — | %0,6 | 24 Haz 2025 |
34İzleyin | CVE-2025-49852İstismar yok | Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premisesassaabloy · control id idsecure · CWE-918 | Yüksek8,7 | — | %0,4 | 24 Haz 2025 |
30İzleyin | CVE-2023-33370İstismar yok | An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSassaabloy · control id idsecure · CWE-755 | Yüksek7,5 | — | %0,6 | 2 Ağu 2023 |
26İzleyin | CVE-2023-33368İstismar yok | Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these assaabloy · control id idsecure · CWE-668 | Orta6,5 | — | %0,5 | 2 Ağu 2023 |
26İzleyin | CVE-2023-26943İstismar yok | Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the origassaabloy · yale keyless smart lock firmware · CWE-326 | Orta6,5 | — | %0,2 | 4 Ara 2023 |
26İzleyin | CVE-2023-26942İstismar yok | Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical proximity to the origassaabloy · yale ia-210 firmware · CWE-326 | Orta6,5 | — | %0,2 | 4 Ara 2023 |
26İzleyin | CVE-2023-26941İstismar yok | Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the origassaabloy · yale conexis l1 firmware · CWE-326 | Orta6,5 | — | %0,2 | 4 Ara 2023 |
24İzleyin | CVE-2023-2044İstismar yok | Control iD iDSecure Dispositivos Page cross site scriptingassaabloy · control id idsecure · CWE-79 | Orta6,1 | — | %0,4 | 14 Nis 2023 |
23İzleyin | CVE-2019-13604İstismar yok | There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24.assaabloy · hid digitalpersona 4500 firmware · CWE-327 | Orta5,9 | — | %1,1 | 15 Tem 2019 |
23İzleyin | CVE-2026-3315İstismar yok | Local Privilege Escalation Due to Writable Executable in Privileged Visionline Service Pathassaabloy · visionline · CWE-250 | Orta5,8 | — | %0,2 | 10 Mar 2026 |
21İzleyin | CVE-2023-4392İstismar yok | Control iD Gerencia Web Cookie cleartext storageassaabloy · control id gerencia web · CWE-312 | Orta5,3 | — | %0,6 | 16 Ağu 2023 |
21İzleyin | CVE-2025-2125İstismar yok | Control iD RH iD PDF Document companyId resource injectionassaabloy · control id rhid · CWE-99 | Orta5,3 | — | %0,3 | 9 Mar 2025 |
- CVE-2020-1017640Planlayın
ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.
KritikCVSS 9,8İstismar yokEPSS %2assaabloy · yale wipc-301w firmware7 May 2020
- CVE-2020-2382639İzleyin
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API.
YüksekCVSS 8,8İstismar yokEPSS %13assaabloy · yale wipc-303w firmware26 Oca 2021
- CVE-2023-3336739İzleyin
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the
KritikCVSS 9,8İstismar yokEPSS %1assaabloy · control id idsecure4 Ağu 2023
- CVE-2023-3337139İzleyin
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers
KritikCVSS 9,8İstismar yokEPSS %1assaabloy · control id idsecure2 Ağu 2023
- CVE-2023-204339İzleyin
Control iD RHiD Edit a sql injection
KritikCVSS 9,8İstismar yokEPSS %1assaabloy · control id rhid14 Nis 2023
- CVE-2025-4985337İzleyin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premises
KritikCVSS 9,3İstismar yokEPSS %0assaabloy · control id idsecure24 Haz 2025
- CVE-2023-3336936İzleyin
A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure fi
KritikCVSS 9,1İstismar yokEPSS %1assaabloy · control id idsecure2 Ağu 2023
- CVE-2025-4985134İzleyin
Improper Authentication in ControlID iDSecure On-premises
YüksekCVSS 8,7İstismar yokEPSS %1assaabloy · control id idsecure24 Haz 2025
- CVE-2025-4985234İzleyin
Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premises
YüksekCVSS 8,7İstismar yokEPSS %0assaabloy · control id idsecure24 Haz 2025
- CVE-2023-3337030İzleyin
An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDS
YüksekCVSS 7,5İstismar yokEPSS %1assaabloy · control id idsecure2 Ağu 2023
- CVE-2023-3336826İzleyin
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these
OrtaCVSS 6,5İstismar yokEPSS %1assaabloy · control id idsecure2 Ağu 2023
- CVE-2023-2694326İzleyin
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the orig
OrtaCVSS 6,5İstismar yokEPSS %0assaabloy · yale keyless smart lock firmware4 Ara 2023
- CVE-2023-2694226İzleyin
Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical proximity to the orig
OrtaCVSS 6,5İstismar yokEPSS %0assaabloy · yale ia-210 firmware4 Ara 2023
- CVE-2023-2694126İzleyin
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the orig
OrtaCVSS 6,5İstismar yokEPSS %0assaabloy · yale conexis l1 firmware4 Ara 2023
- CVE-2023-204424İzleyin
Control iD iDSecure Dispositivos Page cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %0assaabloy · control id idsecure14 Nis 2023
- CVE-2019-1360423İzleyin
There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24.
OrtaCVSS 5,9İstismar yokEPSS %1assaabloy · hid digitalpersona 4500 firmware15 Tem 2019
- CVE-2026-331523İzleyin
Local Privilege Escalation Due to Writable Executable in Privileged Visionline Service Path
OrtaCVSS 5,8İstismar yokEPSS %0assaabloy · visionline10 Mar 2026
- CVE-2023-439221İzleyin
Control iD Gerencia Web Cookie cleartext storage
OrtaCVSS 5,3İstismar yokEPSS %1assaabloy · control id gerencia web16 Ağu 2023
- CVE-2025-212521İzleyin
Control iD RH iD PDF Document companyId resource injection
OrtaCVSS 5,3İstismar yokEPSS %0assaabloy · control id rhid9 Mar 2025