computrols kayıtları
computrols üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-798 Use of Hard-coded Credentials2
- CWE-326 Inadequate Encryption Strength1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-10850İstismar yok | Computrols CBAS 18.0.0 has Default Credentials.computrols · computrols building automation software · CWE-798 | Kritik9,8 | — | %1,9 | 23 May 2019 |
36İzleyin | CVE-2019-10854İstismar yok | Computrols CBAS 18.0.0 allows Authenticated Command Injection.computrols · computrols building automation software · CWE-77 | Yüksek8,8 | — | %3,0 | 23 May 2019 |
36İzleyin | CVE-2019-10847Kavram kanıtı | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.computrols · computrols building automation software · CWE-352 | Yüksek8,8 | — | %2,4 | 24 May 2019 |
36İzleyin | CVE-2019-10852İstismar yok | Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=startcomputrols · computrols building automation software · CWE-89 | Yüksek8,8 | — | %1,8 | 23 May 2019 |
33İzleyin | CVE-2019-10849Kavram kanıtı | Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.computrols · computrols building automation software · CWE-862 | Yüksek7,5 | — | %9,0 | 23 May 2019 |
32İzleyin | CVE-2019-10853İstismar yok | Computrols CBAS 18.0.0 allows Authentication Bypass.computrols · computrols building automation software | Yüksek8,1 | — | %1,7 | 23 May 2019 |
30İzleyin | CVE-2019-10855İstismar yok | Computrols CBAS 18.0.0 mishandles password hashes.computrols · computrols building automation software · CWE-326 | Yüksek7,5 | — | %1,0 | 23 May 2019 |
26İzleyin | CVE-2019-10851İstismar yok | Computrols CBAS 18.0.0 has hard-coded encryption keys.computrols · computrols building automation software · CWE-798 | Orta6,5 | — | %0,7 | 23 May 2019 |
25İzleyin | CVE-2019-10846Kavram kanıtı | Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via tcomputrols · computrols building automation system · CWE-79 | Orta6,1 | — | %4,7 | 23 May 2019 |
24İzleyin | CVE-2019-10848Kavram kanıtı | Computrols CBAS 18.0.0 allows Username Enumeration.computrols · computrols building automation software · CWE-203 | Orta5,3 | — | %8,5 | 24 May 2019 |
- CVE-2019-1085040Planlayın
Computrols CBAS 18.0.0 has Default Credentials.
KritikCVSS 9,8İstismar yokEPSS %2computrols · computrols building automation software23 May 2019
- CVE-2019-1085436İzleyin
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
YüksekCVSS 8,8İstismar yokEPSS %3computrols · computrols building automation software23 May 2019
- CVE-2019-1084736İzleyin
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
YüksekCVSS 8,8Kavram kanıtıEPSS %2computrols · computrols building automation software24 May 2019
- CVE-2019-1085236İzleyin
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start
YüksekCVSS 8,8İstismar yokEPSS %2computrols · computrols building automation software23 May 2019
- CVE-2019-1084933İzleyin
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
YüksekCVSS 7,5Kavram kanıtıEPSS %9computrols · computrols building automation software23 May 2019
- CVE-2019-1085332İzleyin
Computrols CBAS 18.0.0 allows Authentication Bypass.
YüksekCVSS 8,1İstismar yokEPSS %2computrols · computrols building automation software23 May 2019
- CVE-2019-1085530İzleyin
Computrols CBAS 18.0.0 mishandles password hashes.
YüksekCVSS 7,5İstismar yokEPSS %1computrols · computrols building automation software23 May 2019
- CVE-2019-1085126İzleyin
Computrols CBAS 18.0.0 has hard-coded encryption keys.
OrtaCVSS 6,5İstismar yokEPSS %1computrols · computrols building automation software23 May 2019
- CVE-2019-1084625İzleyin
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via t
OrtaCVSS 6,1Kavram kanıtıEPSS %5computrols · computrols building automation system23 May 2019
- CVE-2019-1084824İzleyin
Computrols CBAS 18.0.0 allows Username Enumeration.
OrtaCVSS 5,3Kavram kanıtıEPSS %8computrols · computrols building automation software24 May 2019