Vendor
Paradox Security Systems
Products
5
CVEs
4
Across products
6
Status
Private
Products
5- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-25189 | Cri | 0.64 | 9.8 | 0.03 | Nov 21, 2020 | The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09). | ||
| CVE-2020-25185 | Hig | 0.57 | 8.8 | 0.02 | Nov 21, 2020 | The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09). | ||
| CVE-2023-24709 | Hig | 0.55 | 7.5 | 0.44 | Mar 21, 2023 | An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters. | ||
| CVE-2024-5676 | Med | 0.44 | 6.8 | 0.00 | Jun 19, 2024 | The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system. |
- risk 0.64cvss 9.8epss 0.03
The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).
- risk 0.57cvss 8.8epss 0.02
The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).
- risk 0.55cvss 7.5epss 0.44
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.
- risk 0.44cvss 6.8epss 0.00
The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.