Kalkitech's vulnerability profile centers on a line of embedded networking and synchronization appliances, specifically its Sync series devices across multiple hardware and firmware revisions. The observed disclosures reflect the challenges of characterizing firmware-level flaws where detailed weakness information has not yet been fully classified, leaving the structural attack surface of these edge devices as the primary signal for defenders tracking this vendor.
The number and severity of CVEs published that impact products developed by Kalkitech over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11536CRITICAL Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an attacker t | May 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2021-44564HIGH A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file | Jan 6, 2022 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kalkitech.
Media articles that mention a CVE ID that affects a product developed by Kalkitech — matched by CVE ID, not by vendor name.