VYPR

Evolution Controller

by Evolution Controller

CVEs (8)

  • CVE-2024-29836CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site.

  • CVE-2024-29837HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.

  • CVE-2024-29843HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levels

  • CVE-2024-29842HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the abacard field of any user

  • CVE-2024-29841HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user

  • CVE-2024-29840HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user

  • CVE-2024-29839HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user

  • CVE-2024-29838HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software