Elvexys develops a focused line of streaming and firmware products, with vulnerabilities concentrating in StreamX and its embedded firmware components around path-traversal and hard-coded credential weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elvexys over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4779CRITICAL StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme.
StreamX applications using StreamView | Dec 29, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-4780HIGH ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.
| Dec 29, 2022 | 7.8 | 22 | NO | NO |
CVE-2022-4778MEDIUM StreamX applications from versions 6.02.01 to 6.04.34 are affected by a path traversal vulnerability that allows authenticated users to get unauthorized access to files on the serv | Dec 29, 2022 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elvexys.
Media articles that mention a CVE ID that affects a product developed by Elvexys — matched by CVE ID, not by vendor name.