KMC Controls' vulnerability profile centers on building automation and control (BAC) hardware and firmware, specifically products in the BAC-5051E and BAC-A1616BC product lines. The observed exposure recurs through application-layer weaknesses including cross-site request forgery and improper access control, which are characteristic of web-based management interfaces in networked control systems.
The number and severity of CVEs published that impact products developed by Kmc Controls over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7233CRITICAL KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file. | Jan 19, 2020 | 9.8 | 31 | NO | NO |
CVE-2016-4494HIGH Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows remote attackers to hijack the authentication of unspecified | Jun 10, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-4495MEDIUM KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors. | Jun 10, 2016 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kmc Controls.
Media articles that mention a CVE ID that affects a product developed by Kmc Controls — matched by CVE ID, not by vendor name.