Uc 500e Firmware
by Efacec
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-50703 | Med | 0.41 | 6.3 | 0.00 | Dec 20, 2023 | An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application. | ||
| CVE-2023-50705 | Med | 0.34 | 5.3 | 0.01 | Dec 20, 2023 | An attacker could create malicious requests to obtain sensitive information about the web server. | ||
| CVE-2023-50704 | Med | 0.28 | 4.3 | 0.00 | Dec 20, 2023 | An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users. | ||
| CVE-2023-50706 | Med | 0.27 | 4.1 | 0.00 | Dec 20, 2023 | A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens. |
- risk 0.41cvss 6.3epss 0.00
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.
- risk 0.34cvss 5.3epss 0.01
An attacker could create malicious requests to obtain sensitive information about the web server.
- risk 0.28cvss 4.3epss 0.00
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.
- risk 0.27cvss 4.1epss 0.00
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.