Hidglobal
hidglobal
17 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (17)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hidglobal 2Iclass Se Reader Configuration Cards Firmware Omnikey Secure Elements Reader Configuration Cards FirmwareJun 17, 2026 Feb 7, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys. |
1Hidglobal 8Iclass Se Cp1000 Encoder Firmware Iclass Se Processors FirmwareIclass Se Reader Modules Firmware+5 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys. |
The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account cre...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP150...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury In...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP45...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mer...Show more |
1Hidglobal 2Omnikey 5127 Firmware Omnikey 5427 FirmwareJun 17, 2026 Mar 24, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malf...Show more |
1Hidglobal 1Digital Persona U.are.u 4500 Driver Firmware Jun 17, 2026 Jul 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user...Show more |
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. |
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized acti...Show more |
EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will. |
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attac...Show more |