Vulnerabilities > Qolsys

DATE CVE VULNERABILITY TITLE RISK
2015-10-31 CVE-2015-6033 Cryptographic Issues vulnerability in Qolsys IQ Panel
Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass intended access restrictions via a modified update.
network
qolsys CWE-310
critical
9.3
2015-10-31 CVE-2015-6032 Credentials Management vulnerability in Qolsys IQ Panel
Qolsys IQ Panel (aka QOL) before 1.5.1 has hardcoded cryptographic keys, which allows remote attackers to create digital signatures for code by leveraging knowledge of a key from a different installation.
network
qolsys CWE-255
critical
9.3