apsystems CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

apsystems vulnerability overview

Aggregates CVE and security vulnerability intelligence across all apsystems-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk command injection and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-31502 Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php. [email protected] 7.2 0.94% 2023-05-11 2025-01-27
CVE-2023-28343 OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php. [email protected] 9.8 93.79% 2023-03-14 2024-11-21
CVE-2022-45699 Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter. [email protected] 9.8 89.95% 2023-02-10 2025-06-17
CVE-2022-44037 An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin rights without authenticating allows him to perform multiple attacks, such as attacking wireless network in the product's range. [email protected] 8.8 0.06% 2022-11-29 2025-04-25
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence