|
222501
|
4.6 |
MEDIUM
Physics
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use thes…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-18256
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222502
|
4.6 |
MEDIUM
Physics
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data a…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-18254
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222503
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials u…
|
CWE-287
Improper Authentication
|
CVE-2019-18252
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222504
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credenti…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18248
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222505
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.
|
CWE-287
Improper Authentication
|
CVE-2019-18246
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222506
|
7.5 |
HIGH
Network
|
fortinet
|
fortios
|
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-17655
|
2024-11-21 13:32 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222507
|
7.8 |
HIGH
Local
|
asus
|
aura_sync
|
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gai…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17603
|
2024-11-21 13:32 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222508
|
5.3 |
MEDIUM
Network
|
apache
|
rocketmq
|
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a to…
|
CWE-22
Path Traversal
|
CVE-2019-17572
|
2024-11-21 13:32 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222509
|
9.8 |
CRITICAL
Network
|
apache
|
cloudstack
|
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-17562
|
2024-11-21 13:32 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222510
|
5.4 |
MEDIUM
Network
|
apache
|
syncope
|
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17557
|
2024-11-21 13:32 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|