Synthesis Image System

Vendor:

First CVE: Jun 16, 2024 · Active for 2 years

4
Total CVEs
More Total CVEs than 75% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Synthesis Image System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2024
2 years ago
Most Recent CVE
Jun 16, 2024
772 days ago

CVE Severity & Scoring

Synthesis Image System4 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
Jun 16, 20249.827NONO
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
Jun 16, 20249.826NONO
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.
Jun 16, 20247.521NONO
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.
Jun 16, 20245.317NONO

Exploit Exposure

Signals from CVEs in this product scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (4 CVEs).

Media Mentions

Signals from CVEs in this product scope (4 CVEs).

Top CNAs Publishing CVEs For Synthesis Image System

Top CWEs

Versions

No cataloged versions.