CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareNov 21, 2024 Oct 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative...Show more |
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareNov 21, 2024 Oct 26, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers c...Show more |
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareNov 21, 2024 Oct 26, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without...Show more |
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareNov 21, 2024 Oct 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
|
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareNov 21, 2024 Oct 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain acc...Show more |
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareNov 21, 2024 Oct 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.
|
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareNov 21, 2024 Oct 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.
|