mersive kayıtları
mersive üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-307 Improper Restriction of Excessive Authentication Attempts2
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-12945Kavram kanıtı | Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers tomersive · solstice firmware · CWE-78 | Yüksek8,8 | — | %17,5 | 27 Kas 2019 |
31İzleyin | CVE-2020-27523İstismar yok | Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_namersive · solstice pod firmware · CWE-134 | Yüksek7,5 | — | %2,0 | 11 Kas 2020 |
30İzleyin | CVE-2020-35587İstismar yok | In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled.mersive · solstice firmware · CWE-311 | Yüksek7,5 | — | %1,5 | 23 Ara 2020 |
30İzleyin | CVE-2020-35585İstismar yok | In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Conmersive · solstice pod firmware · CWE-307 | Yüksek7,5 | — | %1,4 | 23 Ara 2020 |
30İzleyin | CVE-2020-35586İstismar yok | In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/inmersive · solstice pod firmware · CWE-307 | Yüksek7,5 | — | %1,4 | 23 Ara 2020 |
27İzleyin | CVE-2025-66573İstismar yok | Solstice Pod API Session Key Extraction via API Endpointmersive · solstice pod firmware · CWE-319 | Orta6,9 | — | %0,3 | 4 Ara 2025 |
23İzleyin | CVE-2020-35584İstismar yok | In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature.mersive · solstice pod firmware · CWE-319 | Orta5,9 | — | %0,8 | 23 Ara 2020 |
- CVE-2017-1294540Planlayın
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to
YüksekCVSS 8,8Kavram kanıtıEPSS %17mersive · solstice firmware27 Kas 2019
- CVE-2020-2752331İzleyin
Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_na
YüksekCVSS 7,5İstismar yokEPSS %2mersive · solstice pod firmware11 Kas 2020
- CVE-2020-3558730İzleyin
In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled.
YüksekCVSS 7,5İstismar yokEPSS %1mersive · solstice firmware23 Ara 2020
- CVE-2020-3558530İzleyin
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Con
YüksekCVSS 7,5İstismar yokEPSS %1mersive · solstice pod firmware23 Ara 2020
- CVE-2020-3558630İzleyin
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/in
YüksekCVSS 7,5İstismar yokEPSS %1mersive · solstice pod firmware23 Ara 2020
- CVE-2025-6657327İzleyin
Solstice Pod API Session Key Extraction via API Endpoint
OrtaCVSS 6,9İstismar yokEPSS %0mersive · solstice pod firmware4 Ara 2025
- CVE-2020-3558423İzleyin
In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature.
OrtaCVSS 5,9İstismar yokEPSS %1mersive · solstice pod firmware23 Ara 2020