Schrack's vulnerability footprint centers on its Technik Microcontrol product line, a modestly represented family of industrial control and automation devices. The durable signal reflects application-layer weaknesses including improper authentication mechanisms and cross-site scripting issues that are typical of embedded web interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schrack over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8329HIGH Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obt | Oct 20, 2014 | 10.0 | 25 | NO | NO |
CVE-2014-5396HIGH The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attacker | Aug 22, 2014 | 7.5 | 25 | NO | NO |
CVE-2014-5382MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Schrack Technik microControl with firmware 1.7.0 (937) allow remote attackers to inject arbitrary web sc | Aug 20, 2014 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schrack.
Media articles that mention a CVE ID that affects a product developed by Schrack — matched by CVE ID, not by vendor name.