Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Secure Boot Stick Firmware CRITICAL 9.8
CVE-2018-12336

Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH acc…

Mitigation only
Fix from $2,300 2018-06-17
System Management Appliance CRITICAL 9.8
CVE-2018-12338

Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipula…

Mitigation only
Fix from $2,300 2018-06-17
Secure Boot Stick Firmware HIGH 8.1
CVE-2018-12330

Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via compro…

Mitigation only
Fix from $1,950 2018-06-17
Secure Boot Stick Firmware HIGH 8.1
CVE-2018-12333

Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security rele…

No fix yet
Fix from $1,950 2018-06-17
Secure Boot Stick Firmware HIGH 7.5
CVE-2018-12334

Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a virt…

Mitigation only
Fix from $1,950 2018-06-17
System Management Appliance HIGH 7.4
CVE-2018-12331

Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to compromis…

Mitigation only
Fix from $1,950 2018-06-17
System Management Appliance HIGH 7.3
CVE-2018-12335

Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipul…

Mitigation only
Fix from $1,950 2018-06-17
Secure Boot Stick Firmware MEDIUM 5.9
CVE-2018-12329

Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.

No fix yet
Fix from $1,600 2018-06-17
Embedded Web Servers CRITICAL 9.8
CVE-2017-1000020

SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by …

Fix: after 1.3.1
Fix from $2,300 2017-07-17