Vulnerabilities > Prominent

DATE CVE VULNERABILITY TITLE RISK
2017-10-17 CVE-2017-14013 Incorrect Resource Transfer Between Spheres vulnerability in Prominent Multiflex M10A Controller Firmware
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface.
network
high complexity
prominent CWE-669
5.6
2017-10-17 CVE-2017-14011 Cross-Site Request Forgery (CSRF) vulnerability in Prominent Multiflex M10A Controller Firmware
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface.
network
low complexity
prominent CWE-352
8.8
2017-10-17 CVE-2017-14009 Cleartext Transmission of Sensitive Information vulnerability in Prominent Multiflex M10A Controller Firmware
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface.
network
low complexity
prominent CWE-319
6.5
2017-10-17 CVE-2017-14007 Insufficient Session Expiration vulnerability in Prominent Multiflex M10A Controller Firmware
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface.
network
high complexity
prominent CWE-613
5.6
2017-10-17 CVE-2017-14005 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Prominent Multiflex M10A Controller Firmware
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface.
network
low complexity
prominent CWE-640
8.8