|
210031
|
8.1 |
HIGH
Network
|
trendmicro
|
deep_security_manager vulnerability_protection
|
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted orga…
|
CWE-287
Improper Authentication
|
CVE-2020-15601
|
2024-11-21 14:05 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210032
|
5.5 |
MEDIUM
Local
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15485
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210033
|
6.5 |
MEDIUM
Adjacent
|
drtrust
|
electrocardiogram_pen_firmware
|
An issue was discovered on Dr Trust ECG Pen 2.00.08 devices. Because the Bluetooth LE support is implemented without a requirement for pairing or security, any attacker can access the GATT server of …
|
NVD-CWE-noinfo
|
CVE-2020-15486
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210034
|
6.8 |
MEDIUM
Physics
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15483
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210035
|
7.8 |
HIGH
Local
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker …
|
CWE-287 CWE-319
Improper Authentication Cleartext Transmission of Sensitive Information
|
CVE-2020-15482
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210036
|
7.5 |
HIGH
Network
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15484
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210037
|
6.1 |
MEDIUM
Network
|
asus
|
rt-ac1900p_firmware
|
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15499
|
2024-11-21 14:05 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210038
|
5.9 |
MEDIUM
Network
|
asus
|
rt-ac1900p_firmware
|
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-15498
|
2024-11-21 14:05 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210039
|
8.8 |
HIGH
Network
|
marvell
|
qconvergeconsole
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability,…
|
-
|
CVE-2020-15645
|
2024-11-21 14:05 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210040
|
8.8 |
HIGH
Network
|
marvell
|
qconvergeconsole
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability,…
|
-
|
CVE-2020-15644
|
2024-11-21 14:05 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|