Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Steve Knabe

#16684of 53,633
16.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2025-48211
9.2
2025-11-27
Alc · Alc Webctrl · CVE-2024-5539
**Name of the Vulnerable Software and Affected Versions** ALC WebCTRL versions prior to 8.6 Carrier i-Vu versions prior to 8.6 **Description** An access control bypass exists in ALC WebCTRL and Carrier i-Vu. This allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web-based building automation server. An unauthenticated attacker can remotely access sensitive building management system data. **Recommendations** Update ALC WebCTRL to a version prior to 8.6. Update Carrier i-Vu to a version prior to 8.6.
PT-2025-48212
6.9
2025-11-27
Alc · Alc Webctrl · CVE-2024-5540
**Name of the Vulnerable Software and Affected Versions** ALC WebCTRL and Carrier i-Vu versions prior to 8.0 **Description** A reflective cross-site scripting issue exists in login panels. This allows a malicious actor to compromise the client browser. **Recommendations** Update ALC WebCTRL and Carrier i-Vu to version 8.0 or later.