osram kayıtları
osram üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-254 7PK - Security Features2
- CWE-284 Improper Access Control2
- CWE-306 Missing Authentication for Critical Function1
- CWE-326 Inadequate Encryption Strength1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2016-5053İstismar yok | OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.osram · lightify home · CWE-306 | Kritik9,8 | — | %2,7 | 9 Nis 2017 |
30İzleyin | CVE-2016-5051İstismar yok | OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.osram · lightify home · CWE-200 | Yüksek7,5 | — | %1,4 | 9 Nis 2017 |
30İzleyin | CVE-2016-5057İstismar yok | OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.osram · lightify pro · CWE-254 | Yüksek7,5 | — | %1,2 | 9 Nis 2017 |
30İzleyin | CVE-2016-5054İstismar yok | OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.osram · lightify home · CWE-284 | Yüksek7,5 | — | %1,1 | 9 Nis 2017 |
30İzleyin | CVE-2016-5058İstismar yok | OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.osram · lightify pro · CWE-284 | Yüksek7,5 | — | %1,1 | 9 Nis 2017 |
30İzleyin | CVE-2016-5052İstismar yok | OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.osram · lightify home · CWE-254 | Yüksek7,5 | — | %1,1 | 9 Nis 2017 |
30İzleyin | CVE-2016-5056İstismar yok | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.osram · lightify pro · CWE-326 | Yüksek7,5 | — | %0,9 | 9 Nis 2017 |
26İzleyin | CVE-2016-5059İstismar yok | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/vosram · lightify pro · CWE-200 | Orta6,5 | — | %1,2 | 9 Nis 2017 |
24İzleyin | CVE-2016-5055İstismar yok | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.osram · lightify pro · CWE-79 | Orta6,1 | — | %0,8 | 9 Nis 2017 |
- CVE-2016-505340Planlayın
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.
KritikCVSS 9,8İstismar yokEPSS %3osram · lightify home9 Nis 2017
- CVE-2016-505130İzleyin
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.
YüksekCVSS 7,5İstismar yokEPSS %1osram · lightify home9 Nis 2017
- CVE-2016-505730İzleyin
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
YüksekCVSS 7,5İstismar yokEPSS %1osram · lightify pro9 Nis 2017
- CVE-2016-505430İzleyin
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.
YüksekCVSS 7,5İstismar yokEPSS %1osram · lightify home9 Nis 2017
- CVE-2016-505830İzleyin
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.
YüksekCVSS 7,5İstismar yokEPSS %1osram · lightify pro9 Nis 2017
- CVE-2016-505230İzleyin
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
YüksekCVSS 7,5İstismar yokEPSS %1osram · lightify home9 Nis 2017
- CVE-2016-505630İzleyin
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.
YüksekCVSS 7,5İstismar yokEPSS %1osram · lightify pro9 Nis 2017
- CVE-2016-505926İzleyin
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/v
OrtaCVSS 6,5İstismar yokEPSS %1osram · lightify pro9 Nis 2017
- CVE-2016-505524İzleyin
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
OrtaCVSS 6,1İstismar yokEPSS %1osram · lightify pro9 Nis 2017