Xovis develops people-counting and occupancy-sensing systems deployed in retail, transportation, and venue environments, with its vulnerability footprint concentrated in firmware and management interfaces across its PC2 and PC3 product lines. The observed weakness classes—cross-site request forgery, path traversal, and improper XML entity handling—reflect common input-validation and access-control gaps in embedded web-based management consoles. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xovis over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11720HIGH Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal. | Aug 30, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-11718HIGH Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF. | Aug 30, 2018 | 8.8 | 22 | NO | NO |
CVE-2018-11719MEDIUM Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE. | Aug 30, 2018 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xovis.
Media articles that mention a CVE ID that affects a product developed by Xovis — matched by CVE ID, not by vendor name.