Vulnerabilities > Hidglobal > High

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-22388 Insecure Default Initialization of Resource vulnerability in Hidglobal products
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed.
local
low complexity
hidglobal CWE-1188
7.8
2023-06-07 CVE-2023-2904 Modification of Assumed-Immutable Data (MAID) vulnerability in Hidglobal Safe
The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API).
network
low complexity
hidglobal CWE-471
7.3
2022-06-06 CVE-2022-31481 Classic Buffer Overflow vulnerability in multiple products
An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer.
network
low complexity
hidglobal carrier CWE-120
7.5
2022-06-06 CVE-2022-31482 Classic Buffer Overflow vulnerability in multiple products
An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer.
network
low complexity
hidglobal carrier CWE-120
7.8
2019-03-21 CVE-2018-17491 Missing Authorization vulnerability in Hidglobal Easylobby Solo 11.0.4563
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system.
local
low complexity
hidglobal CWE-862
7.2