10
CVSSv2

CVE-2019-11536

Published: 22/05/2019 Updated: 24/08/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an malicious user to inject client-side commands or scripts to be executed on the device with privileged access, aka CYB/2019/19561. The attack requires network connectivity to the device and exploits the webserver interface, typically through a browser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kalkitech sync3000_firmware 3.5.0

kalkitech sync3000_firmware 3.6.0

kalkitech sync3000_firmware 3.6.1

kalkitech sync3000_firmware 2.22.6

kalkitech sync3000_firmware 2.23.0

kalkitech sync3000_firmware 2.24.0

kalkitech sync3000_firmware 3.0.0

kalkitech sync3000_firmware 3.1.0

kalkitech sync3000_firmware 3.2.3

kalkitech sync3000_firmware 3.1.16

kalkitech sync3000_firmware 3.2.6