Vulnerabilities > Brivo > Acs100 Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-02-19 CVE-2023-6259 Insufficiently Protected Credentials vulnerability in Brivo Acs100 Firmware and Acs300 Firmware
Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 before 6.2.4.3.
low complexity
brivo CWE-522
4.6
2024-02-19 CVE-2023-6260 OS Command Injection vulnerability in Brivo Acs100 Firmware and Acs300 Firmware
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Security.This issue affects ACS100 (Network Adjacent Access), ACS300 (Physical Access): from 5.2.4 before 6.2.4.3.
low complexity
brivo CWE-78
8.8