VYPR

Jenesys Bas Bridge

Sign in to watch

by Lynxspring

CVEs (4)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-8378Cri0.649.80.01Feb 13, 2017An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.
CVE-2016-8369Hig0.578.80.00Feb 13, 2017An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request (CROSS-SITE REQUEST FORGERY).
CVE-2016-8361Hig0.568.60.00Feb 13, 2017An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
CVE-2016-8357Hig0.467.10.00Feb 13, 2017An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only access to make changes within the application.