Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | Echelon Smartserver 1 FirmwareEchelon Smartserver 2 FirmwareEchelon I.lon 100 FirmwareEchelon I.lon 600 Firmware | 24/7/2018 | 17/6/2026 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory… | |
| Modificada | Crítica (9.8) | 0.83% | — | Echelon Smartserver 1 FirmwareEchelon Smartserver 2 FirmwareEchelon I.lon 100 FirmwareEchelon I.lon 600 Firmware | 24/7/2018 | 17/6/2026 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP. | |
| Modificada | Crítica (9.8) | 1.3% | — | Echelon Smartserver 1 FirmwareEchelon Smartserver 2 FirmwareEchelon I.lon 100 FirmwareEchelon I.lon 600 Firmware | 24/7/2018 | 17/6/2026 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface. |