Supremainc's vulnerability profile centers on BioStar 2, an access-control and identity-management platform deployed in physical security and facilities environments, where its disclosures recur across input-validation and authentication weaknesses including path traversal, SQL injection, OS command injection, and improper permission preservation. The vendor's exposure reflects typical risks in security appliances handling user input and system commands; public exploit code has been associated with its vulnerabilities. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Supremainc over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15050HIGH An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal. | Jul 13, 2020 | 7.5 | 72 | NO | YES |
CVE-2023-27167MEDIUM Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1. | Mar 29, 2023 | 6.5 | 38 | NO | YES |
CVE-2022-38351HIGH A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page. | Sep 19, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-31923HIGH Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create | May 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-33366HIGH A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitr | Aug 3, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-33364HIGH An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server. | Aug 3, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-33365HIGH A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server. | Aug 3, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-33363HIGH An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers. | Aug 3, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Supremainc.
Media articles that mention a CVE ID that affects a product developed by Supremainc — matched by CVE ID, not by vendor name.