Optergy develops a focused line of building management and energy optimization software, with its vulnerability profile concentrating in products such as Enterprise and Proton. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, reflecting the internet-facing nature and access-control sensitivity of building automation systems. The recurring weakness classes—including CSRF, improper privilege management, missing authorization checks, and open redirects—are characteristic of web-based administrative and control interfaces. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Optergy over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7276CRITICAL Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. | Jul 1, 2019 | 9.8 | 93 | NO | YES |
CVE-2019-7274CRITICAL Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root. | Jul 1, 2019 | 9.8 | 50 | NO | YES |
CVE-2019-7273HIGH Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). | Jul 1, 2019 | 8.8 | 41 | NO | YES |
CVE-2019-7275MEDIUM Optergy Proton/Enterprise devices allow Open Redirect. | Jul 1, 2019 | 6.1 | 35 | NO | YES |
CVE-2019-7272MEDIUM Optergy Proton/Enterprise devices allow Username Disclosure. | Jul 1, 2019 | 5.3 | 27 | NO | YES |
CVE-2019-7278MEDIUM Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service. | Jul 1, 2019 | 6.5 | 20 | NO | NO |
CVE-2019-7279HIGH Optergy Proton/Enterprise devices have Hard-coded Credentials. | Jul 1, 2019 | 7.3 | 19 | NO | NO |
CVE-2019-7277MEDIUM Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure. | Jul 1, 2019 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Optergy.
Media articles that mention a CVE ID that affects a product developed by Optergy — matched by CVE ID, not by vendor name.