CVE Tools

Ecos

10 CVEs tracked since 2018. Since Jun 2018, none of them reached CISA KEV.

Ecos CVEs per month

Jun 2018 to Jun 2018. Point at a month, or focus the strip and use the arrow keys.
Ecos CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-06100

Products

The products that kept showing up in Ecos's monthly top three, with their CVEs summed over those months.

  1. Secure Boot Stick Firmware71 month
  2. System Management Appliance31 month

Latest CVEs

The 11 most recently published vulnerabilities affecting Ecos.

  1. CVE-2018-12329Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.5.9
  2. CVE-2018-12333Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute malicious code.8.1
  3. CVE-2018-12332Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset.4.2
  4. CVE-2018-12331Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to compromise authentication keys and configurations via IP ...7.4
  5. CVE-2018-12338Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurations via remote r...9.8
  6. CVE-2018-12335Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrest...7.3
  7. CVE-2018-12337Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confidential configurations via user-space emulation.4.6
  8. CVE-2018-12336Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.9.8
  9. CVE-2018-12330Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via compromised firmware.8.1
  10. CVE-2018-12334Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a virtualization attack.7.5
  11. CVE-2017-1000020SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending...9.8

The record

Peak rank
#34 in Jun 2018
Busiest month shown
Jun 2018, 10 CVEs
Months with a KEV entry
0 since Jun 2018
Monthly snapshots
1 since 2018
Ecos's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store