CVE-2024-3911: Welotec Smart EMS
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of rendered UI layers or frames.
Affected products
- Welotec Smart EMS: before 3.1.4 (fixed in 3.1.4)
- Welotec VPN Security Suite: before 3.1.4 (fixed in 3.1.4)
Published 2024-04-23. Last modified 2026-06-17.