VYPR
Vendor

Solstice

Products
3
CVEs
5
Across products
7
Status
Private

Products

3

Recent CVEs

5
  • CVE-2025-66573HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this…

  • CVE-2020-35587HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative impact, or instead only facilitates an attack…

  • CVE-2020-35586HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase…

  • CVE-2020-35585HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.

  • CVE-2005-1682May 20, 2005
    risk 0.00cvss epss 0.01

    JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users' e-mail messages by modifying the…