CoolKIt kayıtları
coolkit üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-305 Authentication Bypass by Primary Weakness1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-522 Insufficiently Protected Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2024-7205İstismar yok | sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary usercoolkit · ewelink cloud service · CWE-201 | Kritik9,4 | — | %0,5 | 31 Tem 2024 |
30İzleyin | CVE-2023-6998İstismar yok | Lockscreen bypass in eWeLink Appcoolkit · ewelink · CWE-305 | Yüksek7,7 | — | %0,2 | 30 Ara 2023 |
18İzleyin | CVE-2020-12702Kavram kanıtı | Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 coolkit · ewelink · CWE-327 | Orta4,6 | — | %0,3 | 24 Şub 2021 |
18İzleyin | CVE-2021-27941İstismar yok | Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2coolkit · ewelink · CWE-522 | Orta4,6 | — | %0,2 | 6 May 2021 |
- CVE-2024-720537İzleyin
sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user
KritikCVSS 9,4İstismar yokEPSS %0coolkit · ewelink cloud service31 Tem 2024
- CVE-2023-699830İzleyin
Lockscreen bypass in eWeLink App
YüksekCVSS 7,7İstismar yokEPSS %0coolkit · ewelink30 Ara 2023
- CVE-2020-1270218İzleyin
Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1
OrtaCVSS 4,6Kavram kanıtıEPSS %0coolkit · ewelink24 Şub 2021
- CVE-2021-2794118İzleyin
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2
OrtaCVSS 4,6İstismar yokEPSS %0coolkit · ewelink6 May 2021