Efacec
Products
2- 4 CVEs
- 2 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-50707 | Cri | 0.62 | 9.6 | 0.01 | Dec 20, 2023 | Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device. | ||
| CVE-2023-6689 | Hig | 0.53 | 8.2 | 0.00 | Dec 20, 2023 | A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise the entire web application. | ||
| CVE-2023-50703 | Med | 0.41 | 6.3 | 0.00 | Dec 20, 2023 | An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application. | ||
| CVE-2023-50705 | Med | 0.34 | 5.3 | 0.01 | Dec 20, 2023 | An attacker could create malicious requests to obtain sensitive information about the web server. | ||
| CVE-2023-50704 | Med | 0.28 | 4.3 | 0.00 | Dec 20, 2023 | An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users. | ||
| CVE-2023-50706 | Med | 0.27 | 4.1 | 0.00 | Dec 20, 2023 | A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens. |
- risk 0.62cvss 9.6epss 0.01
Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.
- risk 0.53cvss 8.2epss 0.00
A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise the entire web application.
- risk 0.41cvss 6.3epss 0.00
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.
- risk 0.34cvss 5.3epss 0.01
An attacker could create malicious requests to obtain sensitive information about the web server.
- risk 0.28cvss 4.3epss 0.00
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.
- risk 0.27cvss 4.1epss 0.00
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.