Ecos develops a focused line of security-focused hardware appliances and embedded systems, including secure boot devices and system management products, that operate in sensitive infrastructure roles. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes centered on authentication bypass, credential exposure, and insufficient information handling—attack surfaces that are particularly consequential in boot-time and management contexts where trust assumptions run deep. Defenders should prioritize tracking and patching this vendor's releases for any internet-exposed or supply-chain-critical instances; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecos over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12338CRITICAL Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurat | Jun 17, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-12336CRITICAL Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access. | Jun 17, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-1000020CRITICAL SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devic | Jul 17, 2017 | 9.8 | 27 | NO | NO |
CVE-2018-12333HIGH Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute | Jun 17, 2018 | 8.1 | 24 | NO | NO |
CVE-2018-12330HIGH Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via compromised firmware. | Jun 17, 2018 | 8.1 | 23 | NO | NO |
CVE-2018-12335HIGH Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configura | Jun 17, 2018 | 7.3 | 22 | NO | NO |
CVE-2018-12334HIGH Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a virtualization attack. | Jun 17, 2018 | 7.5 | 22 | NO | NO |
CVE-2018-12331HIGH Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to compromise authentication keys and confi | Jun 17, 2018 | 7.4 | 22 | NO | NO |
CVE-2018-12329MEDIUM Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning. | Jun 17, 2018 | 5.9 | 19 | NO | NO |
CVE-2018-12337MEDIUM Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confidential configurations via user-space em | Jun 17, 2018 | 4.6 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecos.
Media articles that mention a CVE ID that affects a product developed by Ecos — matched by CVE ID, not by vendor name.