VendorsCS Technologiesevolutionany version
Vulnerabilities

CS Technologies Evolution any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-29844
Default credentials on web interface of Evolution Controller Versions allows attackers to login and perform administrative functions
Published 2024-04-14 · Analyzed
9.8EPSS 0.006
CVE-2024-29836
Broken Authentication on USER_CHANGE in Evolution Controller allows unauthenticated account creation and takeover
Published 2024-04-14 · Analyzed
9.8EPSS 0.006
CVE-2024-29837
Poor session management in Evolution Controller allows administrator functionality for unauthenticated connections
Published 2024-04-14 · Analyzed
8.8EPSS 0.005
CVE-2024-29838
Unsanitised variable on DAL_ADD in Evolution Controller causes application level denial of service and crash
Published 2024-04-14 · Analyzed
7.5EPSS 0.005
CVE-2024-29839
Broken Access control on DESKTOP_EDIT_USER_GET_CARD in Evolution Controller allows unauthenticated attackers to retrieve card data values.
Published 2024-04-14 · Analyzed
7.5EPSS 0.005
CVE-2024-29840
Broken Access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve PIN field values
Published 2024-04-14 · Analyzed
7.5EPSS 0.005
CVE-2024-29841
Broken Access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve keys values
Published 2024-04-14 · Analyzed
7.5EPSS 0.005
CVE-2024-29842
Broken Access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve ABACARD values
Published 2024-04-14 · Analyzed
7.5EPSS 0.005
CVE-2024-29843
Broken Access control on MOBILE_GET_USERS_LIST in Evolution Controller allows unauthenticated user enumeration
Published 2024-04-14 · Analyzed
7.5EPSS 0.005