Vulnerabilities (CVE)

Filtered by vendor Kalkitech Subscribe
Filtered by product Sync3000 Firmware
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-11536 1 Kalkitech 2 Sync3000, Sync3000 Firmware 2024-02-28 10.0 HIGH 9.8 CRITICAL
Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an attacker to inject client-side commands or scripts to be executed on the device with privileged access, aka CYB/2019/19561. The attack requires network connectivity to the device and exploits the webserver interface, typically through a browser.