|
211191
|
7.8 |
HIGH
Local
|
siemens
|
simatic_rtls_locating_manager
|
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-10051
|
2024-11-21 13:54 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211192
|
7.8 |
HIGH
Local
|
siemens
|
simatic_rtls_locating_manager
|
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service executables of the affected application could allow a local attacker to include…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-10050
|
2024-11-21 13:54 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211193
|
7.3 |
HIGH
Local
|
siemens
|
simatic_rtls_locating_manager
|
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts for the services of the affected application could allow a local attacker to incl…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-10049
|
2024-11-21 13:54 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211194
|
7.6 |
HIGH
Physics
|
ncr
|
aptra_xfs
|
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restar…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-10126
|
2024-11-21 13:54 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211195
|
7.6 |
HIGH
Physics
|
ncr
|
aptra_xfs
|
NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical a…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-10125
|
2024-11-21 13:54 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211196
|
7.1 |
HIGH
Physics
|
ncr
|
aptra_xfs
|
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical acces…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-10124
|
2024-11-21 13:54 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211197
|
5.3 |
MEDIUM
Physics
|
ncr
|
aptra_xfs
|
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with phy…
|
CWE-287
Improper Authentication
|
CVE-2020-10123
|
2024-11-21 13:54 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211198
|
9.8 |
CRITICAL
Network
|
siemens
|
desigo_consumption_control_compact desigo_consumption_control
|
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) th…
|
CWE-94
Code Injection
|
CVE-2020-10055
|
2024-11-21 13:54 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211199
|
8.8 |
HIGH
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error in the challenge-response procedure could allow an attacker…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-10045
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211200
|
7.5 |
HIGH
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the network could be able to install spec…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10044
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|