Integrated Control Technology LTD maintains access-control and security management products, including the Protege GX and Protege WX physical-security platforms and their associated firmware, where observed vulnerabilities center on web-application input handling and credential-storage practices. The recurring weakness classes—cross-site scripting in web interfaces and insufficient password-hashing computational effort—reflect the authentication and administrative-access boundary typical of security appliances. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Integrated Control Technology LTD over time
Of all the CVEs published by Integrated Control Technology LTD as a CNA, 0.0% affect products that Integrated Control Technology LTD develops as a vendor.
Of all the CVEs published that affect products developed by Integrated Control Technology LTD, 0.0% are self-published by Integrated Control Technology LTD as a CNA.
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29734MEDIUM A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into th | Jun 2, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-29731MEDIUM An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users. | Jun 2, 2022 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Integrated Control Technology LTD.
Media articles that mention a CVE ID that affects a product developed by Integrated Control Technology LTD — matched by CVE ID, not by vendor name.