UPC's vulnerability profile centers on consumer cable modem and gateway devices, particularly its Connect Box product line deployed across European markets. The recurring weakness class involves cleartext transmission of sensitive information, a characteristic flaw in embedded networking equipment where credential and configuration data may be exposed without encryption; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Upc over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7136HIGH The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it easier for remote attackers to obt | Dec 19, 2013 | 9.3 | 41 | NO | YES |
CVE-2019-19967HIGH The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstr | Dec 25, 2019 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Upc.
Media articles that mention a CVE ID that affects a product developed by Upc — matched by CVE ID, not by vendor name.