Powersc
Vendor:
First CVE: Feb 2, 2024 · Active for 2 years
13
Total CVEs
More Total CVEs than 91% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Powersc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2024
2 years ago
Most Recent CVE
Feb 2, 2024
903 days ago
CVE Severity & Scoring
Powersc13 CVEs
54%
38%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None11 (84.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50940CRITICAL IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the doma | Feb 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-50936HIGH IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 275116.
| Feb 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-50962HIGH IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.
| Feb 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-50939HIGH IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275129. | Feb 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-50937HIGH IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275117.
| Feb 2, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-50935MEDIUM IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality a | Feb 2, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-50326HIGH IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.
| Feb 2, 2024 | 7.5 | 19 | NO | NO |
CVE-2023-50941MEDIUM IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-F | Feb 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-50328MEDIUM IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.
| Feb 2, 2024 | 5.3 | 18 | NO | NO |
CVE-2023-50933MEDIUM IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser | Feb 2, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Powersc
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1 | 13 | 6.7 | 0.4% | 0 | 0 |
| 2.0 | 13 | 6.7 | 0.4% | 0 | 0 |
| 1.3 | 13 | 6.7 | 0.4% | 0 | 0 |