Harman's vulnerability profile centers on a narrow line of professional audio and control-system products, including embedded firmware across its Hermes and AMX device families, which appear as critical infrastructure components in commercial and entertainment venues. Vulnerabilities affecting the vendor skew toward serious outcomes, and the recurring weakness classes—authentication bypasses, insecure credential storage, and OS command injection—reflect the legacy architecture and limited security hardening typical of embedded control systems exposed to networked environments. Defenders should prioritize inventory and network isolation of affected devices, particularly those internet-reachable or accessible from untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Harman over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11224HIGH HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection. | May 15, 2019 | 8.8 | 30 | NO | NO |
CVE-2015-8362CRITICAL The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attacke | Jan 22, 2016 | 9.8 | 26 | NO | NO |
CVE-2016-1984CRITICAL The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers | Jan 22, 2016 | 9.8 | 25 | NO | NO |
CVE-2019-19562MEDIUM An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information. | Nov 16, 2020 | 4.6 | 19 | NO | NO |
CVE-2019-19560MEDIUM An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information. | Nov 16, 2020 | 4.6 | 18 | NO | NO |
CVE-2019-19556MEDIUM An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information. | Nov 16, 2020 | 4.6 | 18 | NO | NO |
A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | Nov 16, 2020 | 2.4 | 15 | NO | NO |
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | Nov 16, 2020 | 2.4 | 15 | NO | NO |
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | Nov 16, 2020 | 2.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Harman.
Media articles that mention a CVE ID that affects a product developed by Harman — matched by CVE ID, not by vendor name.