Known Vulnerabilities for Computrols Building Automation Software by Computrols
Listed below are 9 of the newest known vulnerabilities associated with "Computrols Building Automation Software" by "Computrols".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-10855 json | Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it w... | 7.5 - HIGH | 2019-05-23 | 2020-08-24 |
| CVE-2019-10854 json | Computrols CBAS 18.0.0 allows Authenticated Command Injection. | 8.8 - HIGH | 2019-05-23 | 2019-05-24 |
| CVE-2019-10853 json | Computrols CBAS 18.0.0 allows Authentication Bypass. | 8.1 - HIGH | 2019-05-23 | 2020-08-24 |
| CVE-2019-10852 json | Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=... | 8.8 - HIGH | 2019-05-23 | 2019-11-12 |
| CVE-2019-10851 json | Computrols CBAS 18.0.0 has hard-coded encryption keys. | 6.5 - MEDIUM | 2019-05-23 | 2021-07-21 |
| CVE-2019-10850 json | Computrols CBAS 18.0.0 has Default Credentials. | 9.8 - CRITICAL | 2019-05-23 | 2019-05-24 |
| CVE-2019-10849 json | Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure. | 7.5 - HIGH | 2019-05-23 | 2020-08-24 |
| CVE-2019-10848 json | Computrols CBAS 18.0.0 allows Username Enumeration. | 5.3 - MEDIUM | 2019-05-24 | 2020-08-24 |
| CVE-2019-10847 json | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. | 8.8 - HIGH | 2019-05-24 | 2019-11-12 |