|
210841
|
7.6 |
HIGH
Physics
|
ncr
|
aptra_xfs
|
NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical a…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-10125
|
2024-11-21 13:54 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210842
|
7.1 |
HIGH
Physics
|
ncr
|
aptra_xfs
|
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical acces…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-10124
|
2024-11-21 13:54 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210843
|
5.3 |
MEDIUM
Physics
|
ncr
|
aptra_xfs
|
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with phy…
|
CWE-287
Improper Authentication
|
CVE-2020-10123
|
2024-11-21 13:54 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210844
|
9.8 |
CRITICAL
Network
|
siemens
|
desigo_consumption_control_compact desigo_consumption_control
|
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) th…
|
CWE-94
Code Injection
|
CVE-2020-10055
|
2024-11-21 13:54 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210845
|
8.8 |
HIGH
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error in the challenge-response procedure could allow an attacker…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-10045
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210846
|
7.5 |
HIGH
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the network could be able to install spec…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10044
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210847
|
6.1 |
MEDIUM
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). The web server could allow Cross-Site Scripting (XSS) attacks if uns…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10043
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210848
|
9.8 |
CRITICAL
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A buffer overflow in various positions of the web application might …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10042
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210849
|
6.1 |
MEDIUM
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A stored Cross-Site-Scripting (XSS) vulnerability is present in diff…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10041
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210850
|
5.5 |
MEDIUM
Local
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retriev…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2020-10040
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|