CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.
Optergy Proton/Enterprise devices have Hard-coded Credentials.
Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.
Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure.
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
Optergy Proton/Enterprise devices allow Open Redirect.
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
Optergy Proton/Enterprise devices allow Username Disclosure.
