彙總 harman 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
歷史漏洞主要涉及 命令注入 等安全問題,並影響 軟體部署與生產負載 相關場景。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2019-19563 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | [email protected] | 2.4 | 0.42% | 2020-11-15 | 2026-06-16 |
| CVE-2019-19562 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information. | [email protected] | 4.6 | 0.49% | 2020-11-15 | 2026-06-16 |
| CVE-2019-19561 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | [email protected] | 2.4 | 0.42% | 2020-11-15 | 2026-06-16 |
| CVE-2019-19560 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information. | [email protected] | 4.6 | 0.49% | 2020-11-15 | 2026-06-16 |
| CVE-2019-19557 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | [email protected] | 2.4 | 0.42% | 2020-11-15 | 2026-06-16 |
| CVE-2019-19556 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information. | [email protected] | 4.6 | 0.48% | 2020-11-15 | 2026-06-16 |
| CVE-2019-11224 | HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection. | [email protected] | 8.8 | 6.53% | 2019-05-15 | 2026-06-16 |
| CVE-2016-1984 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362. | [email protected] | 9.8 | 4.05% | 2016-01-22 | 2026-06-16 |
| CVE-2015-8362 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984. | [email protected] | 9.8 | 4.67% | 2016-01-22 | 2026-06-16 |