KMC Controls develops building automation and HVAC control systems, with observed vulnerabilities concentrating in its BAC-A1616BC controller and associated firmware. The durable signal centers on insufficiently protected credential storage, a characteristic weakness in embedded building-control devices where firmware updates and management access often depend on hard-coded or weakly secured authentication material. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kmccontrols over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7233CRITICAL KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file. | Jan 19, 2020 | 9.8 | 31 | NO | NO |
CVE-2016-4494HIGH Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows remote attackers to hijack the authentication of unspecified | Jun 10, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-4495MEDIUM KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors. | Jun 10, 2016 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kmccontrols.
Media articles that mention a CVE ID that affects a product developed by Kmccontrols — matched by CVE ID, not by vendor name.