Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ismartalarm MEDIUM 6.8
CVE-2018-16222

Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an att…

Fix: after 2.0.8
Fix from $1,600 2018-11-20
Cubeone Firmware MEDIUM 5.3
CVE-2018-16224EPSS 7%

Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically…

Fix: after 2.2.4.10
Fix from $1,600 2018-11-20
Cubeone Firmware CRITICAL 9.8
CVE-2017-13664

Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrat…

Fix: after 2.2.4.8
Fix from $2,300 2017-12-01
Cubeone Firmware HIGH 7.5
CVE-2017-13663

Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.

Fix: after 2.2.4.8
Fix from $1,950 2017-12-01
Cubeone Firmware CRITICAL 9.8
CVE-2017-7728

On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to inco…

No fix yet
Fix from $2,300 2017-07-11
Cubeone Firmware HIGH 7.5
CVE-2017-7726

iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.

No fix yet
Fix from $1,950 2017-07-11
Cubeone Firmware HIGH 7.5
CVE-2017-7729

On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.

No fix yet
Fix from $1,950 2017-07-11
Cubeone Firmware HIGH 7.5
CVE-2017-7730

iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.

No fix yet
Fix from $1,950 2017-07-11