Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Efacec

First CVE: Dec 20, 2023Active for: 3 yearsTotal CVEs: 6

Efacec manufactures a narrow line of power-electronics equipment, specifically uninterruptible power supply (UPS) and battery-charging units such as the UC 500E and BCU 500 series, which are deployed in critical infrastructure and industrial settings. The vendor's vulnerability profile centers on configuration and authentication weaknesses endemic to networked hardware management interfaces, including cleartext transmission of credentials, CSRF flaws, improper access controls, and information exposure through inadequate authorization boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Efacec over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2023
2 years ago
Most Recent CVE
Dec 20, 2023
946 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-6689HIGH
A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise
Dec 20, 20238.825NONO
CVE-2023-50707HIGH
Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.
Dec 20, 20237.519NONO
CVE-2023-50704MEDIUM
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks agains
Dec 20, 20236.119NONO
CVE-2023-50703MEDIUM
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.
Dec 20, 20235.918NONO
CVE-2023-50705MEDIUM
An attacker could create malicious requests to obtain sensitive information about the web server.
Dec 20, 20235.317NONO
CVE-2023-50706MEDIUM
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or
Dec 20, 20234.316NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
33%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical1 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Efacec.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Efacec — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Efacec's Products

View all 1 CNAs →

Top CWEs