4st_l-bems vulnerabilities
CVEs whose affected-version data names the 4st_l-bems package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2021-37293Medium· 6.5A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php.
A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php.
▾ Sunlitkevinlab · 4st_l-bemsEPSS 1.4%via NVD
CVE-2021-37292High· 7.2PoCAn Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obta…
▾ Midnightkevinlab · 4st_l-bemsEPSS 6.6%via NVD
CVE-2021-37291Critical· 9.8PoCAn SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
▾ Abyssalkevinlab · 4st_l-bemsEPSS 6.5%via NVD