|
210431
|
9.8 |
CRITICAL
Network
|
abb
|
irb140_firmware irc5_firmware
|
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-10287
|
2024-11-21 13:55 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210432
|
9.1 |
CRITICAL
Network
|
ufactory
|
xarm_studio
|
No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio …
|
NVD-CWE-noinfo
|
CVE-2020-10284
|
2024-11-21 13:55 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210433
|
7.5 |
HIGH
Network
|
samba fedoraproject opensuse debian
|
samba fedora leap debian_linux
|
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-10745
|
2024-11-21 13:55 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210434
|
6.5 |
MEDIUM
Network
|
samba redhat opensuse fedoraproject debian
|
samba storage leap fedora debian_linux
|
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped wit…
|
CWE-476 CWE-416
NULL Pointer Dereference Use After Free
|
CVE-2020-10730
|
2024-11-21 13:55 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210435
|
9.8 |
CRITICAL
Network
|
dronecode
|
micro_air_vehicle_link
|
The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorize…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10282
|
2024-11-21 13:55 |
2020-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210436
|
7.5 |
HIGH
Network
|
dronecode
|
micro_air_vehicle_link
|
This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information provided it has access to the communication medium. MA…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-10281
|
2024-11-21 13:55 |
2020-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210437
|
7.5 |
HIGH
Network
|
honeywell
|
controledge_plc_firmware controledge_rtu_firmware
|
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-10628
|
2024-11-21 13:55 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210438
|
7.5 |
HIGH
Network
|
honeywell
|
controledge_plc_firmware controledge_rtu_firmware
|
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-10624
|
2024-11-21 13:55 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210439
|
5.5 |
MEDIUM
Local
|
apache netapp
|
activemq_artemis oncommand_workflow_automation
|
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properti…
|
CWE-312 CWE-522
Cleartext Storage of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-10727
|
2024-11-21 13:55 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210440
|
6.5 |
MEDIUM
Network
|
redhat fedoraproject opensuse linuxfoundation canonical
|
ceph_storage openstack fedora leap ceph ubuntu_linux
|
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the Exp…
|
CWE-74
Injection
|
CVE-2020-10753
|
2024-11-21 13:55 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|