Syntax: kev:true severity:critical epss:>0.95 vendor:cisco patch:false
Filters
Severity
Exploitation
Data Source
Data Quality
Vendor
CWE — Weakness Type
Clear all
Top 20 matches Showing top matches — use filters or a more specific query to narrow
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.
Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
Page 1+ Next →