Yale Al00a Firmware
Vendor:
First CVE: Aug 14, 2019 · Active for 6 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
40.0%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Yale Al00a Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2019
6 years ago
Most Recent CVE
Dec 27, 2024
578 days ago
CVE Severity & Scoring
Yale Al00a Firmware5 CVEs
40%
60%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (60.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (20.0%)
Adjacent Network1 (20.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (60.0%)
High0 (0.0%)
None2 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 92 | YES | YES |
CVE-2020-0069HIGH In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This co | Mar 10, 2020 | 7.8 | 60 | YES | NO |
CVE-2019-9506HIGH The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length n | Aug 14, 2019 | 8.1 | 21 | NO | NO |
CVE-2020-9081MEDIUM There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Success | Dec 27, 2024 | 6.8 | 20 | NO | NO |
CVE-2020-9235MEDIUM Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earli | Sep 3, 2020 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
2 CVEs
40.0% of CVEs· 99th percentile
Metasploit
1 CVE
20.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Yale Al00a Firmware
Top CWEs
Versions
No cataloged versions.