Kastle develops access control and physical security systems, with its vulnerability footprint centered on its access control firmware and platform components. The observed weakness classes—cleartext storage of sensitive information and use of hard-coded credentials—reflect common challenges in embedded physical security systems where credential management and data protection are critical to security posture. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kastle over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45862HIGH Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information. | Sep 19, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-45861HIGH Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information. | Sep 19, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kastle.
Media articles that mention a CVE ID that affects a product developed by Kastle — matched by CVE ID, not by vendor name.