Vulnerabilities
Vulnerable Software
Secure Elements:  Security Vulnerabilities
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackers to send messages to a protected asset without knowing the proper CEID.
CVSS Score
5.0
EPSS Score
0.033
Published
2006-05-31
The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the console.
CVSS Score
7.5
EPSS Score
0.029
Published
2006-05-31
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain access to the server.
CVSS Score
7.5
EPSS Score
0.029
Published
2006-05-31
Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overwrite arbitrary files (1) on a server during an update or (2) on a client via modified pathnames, possibly due to a directory traversal issue.
CVSS Score
4.0
EPSS Score
0.023
Published
2006-05-31


Contact Us

Shodan ® - All rights reserved