cs-technologies 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
過去の問題は主に パス処理の欠陥 and vendor risk memory corruption などに関し、一部は ファイル上書き を招き、vendor surface software deployment and vendor surface production workloads 関連の場面に影響します。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2024-29844 | Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password. | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 9.8 | 0.09% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29843 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levels | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 7.5 | 0.11% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29842 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the abacard field of any user | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 7.5 | 0.17% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29841 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 7.5 | 0.17% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29840 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 7.5 | 0.17% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29839 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 7.5 | 0.17% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29838 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 7.5 | 0.17% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29837 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in. | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 8.8 | 0.15% | 2024-04-15 | 2025-12-10 |
| CVE-2024-29836 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site. | 430a6cef-dc26-47e3-9fa8-52fb7f19644e | 9.8 | 0.17% | 2024-04-15 | 2025-12-10 |