VendorsSecure Elementsc5_enterprise_vulnerability_managementany version
Vulnerabilities

Secure Elements c5 Enterprise Vulnerability Management any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2006-2715
The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the console.
Published 2006-05-31 · Modified
7.5EPSS 0.022
CVE-2006-2716
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain access to the server.
Published 2006-05-31 · Modified
7.5EPSS 0.022
CVE-2006-2713
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEID of a protected asset, which can be used in other attacks against AVR.
Published 2006-05-31 · Modified
5.0EPSS 0.019
CVE-2006-2714
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackers to send messages to a protected asset without knowing the proper CEID.
Published 2006-05-31 · Modified
5.0EPSS 0.019
CVE-2006-2717
Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overwrite arbitrary files (1) on a server during an update or (2) on a client via modified pathnames, possibly due to a directory traversal issue.
Published 2006-05-31 · Modified
4.0EPSS 0.019