|
210171
|
7.5 |
HIGH
Network
|
privateinternetaccess
|
private_internet_access_vpn_client
|
A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via i…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15590
|
2024-11-21 14:05 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210172
|
9.8 |
CRITICAL
Network
|
accel-ppp
|
accel-ppp
|
In ACCEL-PPP (an implementation of PPTP/PPPoE/L2TP/SSTP), there is a buffer overflow when receiving an l2tp control packet ith an AVP which type is a string and no hidden flags, length set to less th…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-15173
|
2024-11-21 14:05 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210173
|
8.1 |
HIGH
Network
|
trendmicro
|
deep_security_manager vulnerability_protection
|
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targ…
|
CWE-287
Improper Authentication
|
CVE-2020-15605
|
2024-11-21 14:05 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210174
|
8.1 |
HIGH
Network
|
trendmicro
|
deep_security_manager vulnerability_protection
|
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted orga…
|
CWE-287
Improper Authentication
|
CVE-2020-15601
|
2024-11-21 14:05 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210175
|
5.5 |
MEDIUM
Local
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15485
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210176
|
6.5 |
MEDIUM
Adjacent
|
drtrust
|
electrocardiogram_pen_firmware
|
An issue was discovered on Dr Trust ECG Pen 2.00.08 devices. Because the Bluetooth LE support is implemented without a requirement for pairing or security, any attacker can access the GATT server of …
|
NVD-CWE-noinfo
|
CVE-2020-15486
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210177
|
6.8 |
MEDIUM
Physics
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15483
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210178
|
7.8 |
HIGH
Local
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker …
|
CWE-287 CWE-319
Improper Authentication Cleartext Transmission of Sensitive Information
|
CVE-2020-15482
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210179
|
7.5 |
HIGH
Network
|
niscomed
|
m1000_multipara_patient_monitor_firmware
|
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15484
|
2024-11-21 14:05 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210180
|
6.1 |
MEDIUM
Network
|
asus
|
rt-ac1900p_firmware
|
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15499
|
2024-11-21 14:05 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|