Vulnerabilities in HID Mercury
8 resultsVexday analysis
HID Mercury apresenta 8 vulnerabilidades catalogadas, sendo 3 críticas, sem registros de exploração ativa conhecida (KEV). A fraqueza dominante é a falta de autenticação ou autorização (CWE-425), padrão que sugere riscos de acesso não autorizado. O portfólio não registra novas publicações nos últimos 90 dias, indicando risco estabilizado.
CVE-2022-31479CRITICALRemote Code Execution via command injection of the hostnameEPSS 2.4%CVE-2022-31483CRITICALArbitrary file write via authenticated OSDP file uploadEPSS 1.7%CVE-2022-31481CRITICALRemote Code Execution via buffer overflow in firmware update processEPSS 1.5%CVE-2022-31486HIGHCommand injection via Advanced Networking route add functionalityEPSS 1.3%CVE-2022-31482HIGHDenial-of-Service via internal structure overflowEPSS 1.0%CVE-2022-31484HIGHUser Account Deletion UnauthenticatedEPSS 1.0%CVE-2022-31480HIGHUnauthenticated Firmware Upload and Arbitrary RebootEPSS 0.9%CVE-2022-31485MEDIUMUnauthenticated homepage note modificationEPSS 0.8%