Vulnerabilities > Ecos > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-06-17 CVE-2018-12338 Unspecified vulnerability in Ecos System Management Appliance 5.2.68
Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurations via remote root SSH access.
network
low complexity
ecos
critical
9.8
2018-06-17 CVE-2018-12336 Information Exposure vulnerability in Ecos Secure Boot Stick Firmware 5.6.5
Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.
network
low complexity
ecos CWE-200
critical
9.8
2017-07-17 CVE-2017-1000020 Improper Authentication vulnerability in Ecos Embedded web Servers 1.3.1
SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass.
network
low complexity
ecos CWE-287
critical
9.8