|
194431
|
7.8 |
HIGH
Local
|
broadcom
|
fabric_operating_system
|
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid passw…
|
CWE-287
Improper Authentication
|
CVE-2021-27794
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194432
|
5.3 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after…
|
CWE-863
Incorrect Authorization
|
CVE-2021-27793
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194433
|
7.8 |
HIGH
Local
|
broadcom
|
fabric_operating_system
|
The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash…
|
NVD-CWE-noinfo
|
CVE-2021-27792
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194434
|
5.4 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentica…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-27791
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194435
|
7.8 |
HIGH
Local
|
broadcom
|
fabric_operating_system
|
The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-27790
|
2024-11-21 14:58 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194436
|
6.8 |
MEDIUM
Physics
|
vizio
|
p65-f1_firmware e50x-e1_firmware
|
Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, because files on the USB drive are effectiv…
|
NVD-CWE-noinfo
|
CVE-2021-27942
|
2024-11-21 14:58 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194437
|
8.2 |
HIGH
Network
|
ecobee
|
ecobee3_lite_firmware
|
A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wireless Access Control setup process. A threat actor can exploi…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-27954
|
2024-11-21 14:58 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194438
|
7.5 |
HIGH
Network
|
ecobee
|
ecobee3_lite_firmware
|
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a de…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-27953
|
2024-11-21 14:58 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194439
|
9.8 |
CRITICAL
Network
|
ecobee
|
ecobee3_lite_firmware
|
Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27952
|
2024-11-21 14:58 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194440
|
7.5 |
HIGH
Network
|
vizio
|
p65-f1_firmware e50x-e1_firmware
|
The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-27943
|
2024-11-21 14:58 |
2021-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|