Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
113040.6%CRITICAL

Related CVEs

13
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-59392On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.MEDIUM6.88.6%Nov 6, 2025
CVE-2024-46603An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.HIGH7.547.3%Jan 7, 2025
CVE-2024-46602An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.HIGH7.547.3%Jan 7, 2025
CVE-2024-46601Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.HIGH7.546.3%Jan 7, 2025
CVE-2024-22085An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.MEDIUM6.213.5%Mar 20, 2024
CVE-2024-22084An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files.HIGH7.531.2%Mar 20, 2024
CVE-2024-22083An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for further access to the device, including reconfiguration tasks.MEDIUM6.542.0%Mar 20, 2024
CVE-2024-22082An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused be an attacker get a better understanding of the operating system.HIGH7.545.8%Mar 20, 2024
CVE-2024-22081An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.CRITICAL9.851.5%Mar 20, 2024
CVE-2024-22080An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing.CRITICAL9.851.5%Mar 20, 2024
CVE-2024-22079An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.HIGH7.559.0%Mar 20, 2024
CVE-2024-22078An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.HIGH8.846.2%Mar 20, 2024
CVE-2024-22077An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.MEDIUM5.338.0%Mar 20, 2024