Vulnerabilities (CVE)

Filtered by vendor Kalkitech Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44564 1 Kalkitech 40 Sync2000-m1, Sync2000-m1 Firmware, Sync2000-m2 and 37 more 2024-02-28 6.8 MEDIUM 8.1 HIGH
A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and knowledge of its IP address. The attack exploits the unsecured communication channel used between the administration tool Easyconnect and the SYNC device (in the affected family of SYNC products).
CVE-2019-11536 1 Kalkitech 2 Sync3000, Sync3000 Firmware 2024-02-28 10.0 HIGH 9.8 CRITICAL
Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an attacker to inject client-side commands or scripts to be executed on the device with privileged access, aka CYB/2019/19561. The attack requires network connectivity to the device and exploits the webserver interface, typically through a browser.