Showing 3 vulnerabilities on this page for exacqVision Web Service

Signals CISA KEV Ransomware Nuclei
Johnson Controls vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

exacqVision Server 32-bit

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause denial-of-service condition.

CWE-190Oct 11, 2021
CVSS7.5v3.1EPSS1.57%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

exacqVision Web Service

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

CWE-269Oct 11, 2021
CVSS9.8v3.1EPSS1.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

exacqVision Web Service CSS

exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

CWE-79Jun 24, 2021
CVSS5.3v3.1EPSS1.22%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX