Vulnerabilities
Vulnerable Software
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized changes.
CVSS Score
6.5
EPSS Score
0.002
Published
2020-06-16
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.
CVSS Score
9.8
EPSS Score
0.008
Published
2020-06-16


Contact Us

Shodan ® - All rights reserved