Efacec manufactures a narrow line of power-electronics equipment, specifically uninterruptible power supply (UPS) and battery-charging units such as the UC 500E and BCU 500 series, which are deployed in critical infrastructure and industrial settings. The vendor's vulnerability profile centers on configuration and authentication weaknesses endemic to networked hardware management interfaces, including cleartext transmission of credentials, CSRF flaws, improper access controls, and information exposure through inadequate authorization boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Efacec over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6689HIGH
A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise | Dec 20, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-50707HIGH
Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.
| Dec 20, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-50704MEDIUM
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks agains | Dec 20, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-50703MEDIUM
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.
| Dec 20, 2023 | 5.9 | 18 | NO | NO |
CVE-2023-50705MEDIUM
An attacker could create malicious requests to obtain sensitive information about the web server.
| Dec 20, 2023 | 5.3 | 17 | NO | NO |
CVE-2023-50706MEDIUM
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or | Dec 20, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Efacec.
Media articles that mention a CVE ID that affects a product developed by Efacec — matched by CVE ID, not by vendor name.