Secure Elements maintains a focused vulnerability footprint around its Class 5 Enterprise Vulnerability Management platform, a specialized tool deployed in enterprise security operations. The recurring disclosures center on the product itself and reflect the complexity inherent to comprehensive vulnerability assessment and reporting systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Secure Elements over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2715HIGH The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the | May 31, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-2716HIGH Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain access to the server. | May 31, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-2709MEDIUM Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) execute arbitrary code on a client or (2 | May 31, 2006 | 5.0 | 16 | NO | NO |
CVE-2006-2704MEDIUM Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sensitive vulnerability information. | May 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2705MEDIUM Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large number of forged client registration mess | May 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2706MEDIUM Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start" messages that cause AVR to connect to a | May 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2707MEDIUM Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malic | May 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2708MEDIUM Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_S | May 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2710MEDIUM Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers with the key to decrypt communications. | May 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2711MEDIUM Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows re | May 31, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Secure Elements.
Media articles that mention a CVE ID that affects a product developed by Secure Elements — matched by CVE ID, not by vendor name.