Mirasys develops video management and surveillance systems where its vulnerability exposure clusters around access and data-handling weaknesses, including path traversal, cleartext transmission, unsafe deserialization, unrestricted file uploads, and hard-coded credentials. These findings reflect the architectural patterns common to networked video-management platforms that ingest and process untrusted stream data and user input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mirasys over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8727HIGH Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system to access files or directories via the Web Client webserver. | Jun 19, 2018 | 7.5 | 36 | NO | YES |
CVE-2019-11031CRITICAL Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, a | Aug 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11030CRITICAL Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method trigge | Aug 22, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-11029HIGH Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ wit | Aug 22, 2019 | 7.5 | 23 | NO | NO |
CVE-2017-15290HIGH Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in which cleartext data is sent from a server to a client, and n | Oct 12, 2017 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mirasys.
Media articles that mention a CVE ID that affects a product developed by Mirasys — matched by CVE ID, not by vendor name.