|
197141
|
8.1 |
HIGH
Adjacent
|
silabs jasco dome linear
|
500_series_firmware zw4201 dm501 lb60z-1
|
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 vers…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-9058
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197142
|
8.8 |
HIGH
Adjacent
|
linear silabs
|
wapirz-1 wadwaz-1 100_series_firmware 200_series_firmware 300_series_firmware
|
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerab…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-9057
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197143
|
7.1 |
HIGH
Local
|
parallels
|
remote_application_server
|
Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confid…
|
NVD-CWE-Other
|
CVE-2020-8968
|
2024-11-21 14:39 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197144
|
7.8 |
HIGH
Local
|
intel
|
thunderbolt_non-dch_driver
|
Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via loca…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8741
|
2024-11-21 14:39 |
2021-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197145
|
4.1 |
MEDIUM
Network
|
kubernetes
|
kubernetes
|
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver re…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-8561
|
2024-11-21 14:39 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197146
|
7.5 |
HIGH
Network
|
iportalis
|
iportalis_control_portal
|
An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Admi…
|
CWE-20
Improper Input Validation
|
CVE-2020-9002
|
2024-11-21 14:39 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197147
|
7.5 |
HIGH
Network
|
iportalis
|
iportalis_control_portal
|
An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote serve…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9000
|
2024-11-21 14:39 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197148
|
7.3 |
HIGH
Local
|
intel
|
processor_diagnostic_tool
|
Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-8702
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197149
|
6.7 |
MEDIUM
Local
|
intel netapp
|
bios cloud_backup hci_storage_node_bios solidfire_bios hci_compute_node_bios aff_bios fas_bios e-series_bios
|
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-20
Improper Input Validation
|
CVE-2020-8700
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197150
|
6.4 |
MEDIUM
Local
|
intel siemens
|
local_manageability_service simatic_field_pg_m5_firmware simatic_field_pg_m6_firmware simatic_ipc427e_firmware simatic_ipc477e_firmware simatic_ipc477e_pro_firmware simatic_ipc527g_…
|
Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-362
Race Condition
|
CVE-2020-8704
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|