Smartics is a niche vendor whose vulnerability footprint centers on its core product and clusters around access control and input-handling weaknesses, including improper access control, path traversal, and cross-site scripting flaws typical of web-facing applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartics over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2140CRITICAL Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters. | Jun 27, 2022 | 9.0 | 28 | NO | NO |
CVE-2022-2088MEDIUM An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0. | Jun 27, 2022 | 4.9 | 15 | NO | NO |
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitr | Jun 27, 2022 | 2.7 | 12 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartics.
Media articles that mention a CVE ID that affects a product developed by Smartics — matched by CVE ID, not by vendor name.