Cbc manufactures embedded networking and storage appliances, with a documented vulnerability footprint centered on firmware across multiple device models including the DR series and NR-series products. The recurring weaknesses reflect common embedded-device risks: hidden or undocumented functionality, authentication bypass, OS command injection, and missing encryption of sensitive data in transit or at rest. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cbc over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40144HIGH OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the aff | Aug 23, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-38585HIGH Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the | Aug 23, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-40158HIGH Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the aff | Aug 23, 2023 | 8.8 | 22 | NO | NO |
CVE-2019-19464MEDIUM The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics. | Nov 30, 2019 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cbc.
Media articles that mention a CVE ID that affects a product developed by Cbc — matched by CVE ID, not by vendor name.