|
210491
|
6.8 |
MEDIUM
Physics
|
gigadevice
|
gd32f130_firmware
|
Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13468
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210492
|
4.6 |
MEDIUM
Physics
|
cksic
|
cks32f103_firmware
|
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-13467
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210493
|
6.8 |
MEDIUM
Physics
|
st
|
stm32f103_firmware
|
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
|
NVD-CWE-noinfo
|
CVE-2020-13466
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210494
|
6.8 |
MEDIUM
Physics
|
gigadevice
|
gd32f103_firmware
|
The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.
|
CWE-20
Improper Input Validation
|
CVE-2020-13465
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210495
|
4.2 |
MEDIUM
Physics
|
cksic
|
cks32f103_firmware
|
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA modul…
|
CWE-862
Missing Authorization
|
CVE-2020-13464
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210496
|
4.6 |
MEDIUM
Physics
|
apexmic
|
apm32f103_firmware
|
The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-13463
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210497
|
6.1 |
MEDIUM
Network
|
o-dyn
|
collabtive
|
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user h…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13655
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210498
|
6.5 |
MEDIUM
Adjacent
|
espressif
|
esp-idf
|
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion …
|
CWE-617
Reachable Assertion
|
CVE-2020-13595
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210499
|
6.5 |
MEDIUM
Adjacent
|
espressif
|
esp-idf
|
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on …
|
CWE-20
Improper Input Validation
|
CVE-2020-13594
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210500
|
8.8 |
HIGH
Adjacent
|
ti
|
simplelink-cc2640r2_software_development_kit
|
The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connectio…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-13593
|
2024-11-21 14:01 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|