Prise's vulnerability profile concentrates in its Advanced Driver Assistance Systems (ADAS) platform, a specialized automotive software product whose disclosures skew toward serious outcomes including critical severity. The recurring weakness classes—cross-site scripting, cross-site request forgery, sensitive information exposure, code injection, and path traversal—reflect the web-facing and data-handling attack surface typical of in-vehicle or connected automotive control systems. Current exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prise over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15088CRITICAL An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentica | Sep 20, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-15089HIGH An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator. | Sep 20, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-14914CRITICAL An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to an arbitrary file read and deletion via Directory Traversal. | Sep 20, 2019 | 9.1 | 26 | NO | NO |
CVE-2019-15087HIGH An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution. | Sep 20, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-15085HIGH An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form. | Sep 20, 2019 | 7.5 | 22 | NO | NO |
CVE-2019-14916MEDIUM An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload. | Sep 20, 2019 | 6.5 | 21 | NO | NO |
CVE-2019-15086MEDIUM An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message. | Sep 20, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-14915MEDIUM An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submitting a rogue certificate. | Sep 20, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-14911MEDIUM An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to reflected XSS. | Sep 20, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-14912MEDIUM An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie. | Sep 20, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prise.
Media articles that mention a CVE ID that affects a product developed by Prise — matched by CVE ID, not by vendor name.