Brivo develops physical access control systems, including its ACS100 and ACS300 appliances, which manage building entry and credential authentication for enterprise facilities. The recurring vulnerability exposures center on access control logic, OS command injection, and credential protection in the firmware and platform layers of these systems, reflecting the authentication and system-command execution demands of access-management hardware.
The number and severity of CVEs published that impact products developed by Brivo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6260HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Sec | Feb 19, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-6259MEDIUM Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue | Feb 19, 2024 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brivo.
Media articles that mention a CVE ID that affects a product developed by Brivo — matched by CVE ID, not by vendor name.