VYPR

ICS Advisories

by Cisagov

CVEs (31)

  • CVE-2020-14479MedApr 1, 2022
    risk 0.35cvss 5.3epss 0.01

    Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server

  • CVE-2025-71411MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

  • CVE-2025-31147MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

  • CVE-2025-25276MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can hijack other users' devices and potentially control them.

  • CVE-2025-24315MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

  • CVE-2025-31357MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain a user's plant list by knowing the username.

  • CVE-2025-30514MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").

  • CVE-2025-27938MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").

  • CVE-2022-2137MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

  • CVE-2024-38279MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

  • CVE-2024-39278MedSep 5, 2024
    risk 0.27cvss 4.2epss 0.00

    Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.

Page 2 of 2