Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.8
CVE-2018-16222
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an att…
Ismartalarm
after 2.0.8
MEDIUM 5.3
CVE-2018-16224EPSS 7%
Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically…
Cubeone Firmware
after 2.2.4.10
CRITICAL 9.8
CVE-2017-13664
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrat…
Cubeone Firmware
after 2.2.4.8
HIGH 7.5
CVE-2017-13663
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.
Cubeone Firmware
after 2.2.4.8
CRITICAL 9.8
CVE-2017-7728
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to inco…
Cubeone Firmware
No fix yet
HIGH 7.5
CVE-2017-7726
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
Cubeone Firmware
No fix yet
HIGH 7.5
CVE-2017-7729
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
Cubeone Firmware
No fix yet
HIGH 7.5
CVE-2017-7730
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.
Cubeone Firmware
No fix yet