Vulnerabilities > Digital Alert Systems

DATE CVE VULNERABILITY TITLE RISK
2013-06-30 CVE-2013-4735 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 have a default password for an administrative account, which makes it easier for remote attackers to obtain access via an IP network.
network
low complexity
digital-alert-systems monroe-electronics CWE-264
critical
10.0
2013-06-30 CVE-2013-4734 Predictable Password Generation vulnerability in Multiple Vendors Multiple EAS Devices
dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 generates predictable passwords, which might make it easier for attackers to obtain non-administrative access via unspecified vectors.
network
low complexity
digital-alert-systems monroe-electronics
7.5
2013-06-30 CVE-2013-4733 Permissions, Privileges, and Access Controls vulnerability in multiple products
The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log files.
7.8
2013-06-30 CVE-2013-0137 Cryptographic Issues vulnerability in multiple products
The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 contains a known SSH private key, which makes it easier for remote attackers to obtain root access, and spoof alerts, via an SSH session.
network
low complexity
digital-alert-systems monroe-electronics CWE-310
critical
10.0