Vulnerabilities > Easyio

DATE CVE VULNERABILITY TITLE RISK
2020-03-02 CVE-2018-15820 Cross-site Scripting vulnerability in Easyio 30P Firmware 2.0.5.16
EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
network
easyio CWE-79
4.3
2020-03-02 CVE-2018-15819 Improper Authentication vulnerability in Easyio 30P Firmware 2.0.5.16
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
network
low complexity
easyio CWE-287
5.0
2015-09-28 CVE-2015-3974 Credentials Management vulnerability in Easyio Easyio-30P-Sf and Easyio-30P-Sf Firmware
EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/EasyIO, Honeywell Automation India, Johnson Controls, SyxthSENSE, Transformative Wave Technologies, Tridium Asia Pacific, and Tridium Europe products, have a hardcoded password, which makes it easier for remote attackers to obtain access via unspecified vectors.
network
low complexity
easyio CWE-255
critical
9.0