|
210461
|
8.8 |
HIGH
Adjacent
|
philips
|
performancebridge_focal_point patient_information_center_ix
|
In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and
PerformanceBridge Focal Point Version A.01, when an actor claims to have
a given identity, the software does not prove or insu…
|
-
|
CVE-2020-16222
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210462
|
3.5 |
LOW
Adjacent
|
philips
|
patient_information_center_ix
|
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the
software does not neutralize or incorrectly neutralizes
user-controllable input before it is placed in output that is then us…
|
-
|
CVE-2020-16218
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210463
|
5.0 |
MEDIUM
Local
|
philips
|
patient_information_center_ix
|
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the
software saves user-provided information into a comma-separated value
(CSV) file, but it does not neutralize or incorrectly n…
|
-
|
CVE-2020-16214
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210464
|
9.8 |
CRITICAL
Network
|
nagios
|
nagios_xi
|
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was …
|
NVD-CWE-noinfo
|
CVE-2020-15903
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210465
|
5.3 |
MEDIUM
Network
|
siemens
|
spectrum_power_4
|
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.
|
CWE-200
Information Exposure
|
CVE-2020-15790
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210466
|
9.8 |
CRITICAL
Network
|
siemens
|
simatic_hmi_united_comfort_panels_firmware
|
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be trunc…
|
-
|
CVE-2020-15787
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210467
|
5.3 |
MEDIUM
Network
|
siemens
|
siveillance_video_client
|
A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the…
|
-
|
CVE-2020-15785
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210468
|
5.3 |
MEDIUM
Network
|
siemens
|
spectrum_power_4
|
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15784
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210469
|
6.5 |
MEDIUM
Adjacent
|
philips
|
performancebridge_focal_point patient_information_center_ix intellivue_mp2-mp90_firmware intellivue_mx100_firmware intellivue_mx400_firmware intellivue_mx850_firmware intellivue_x2_…
|
In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750,
MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior,
the product receives input or data but does not validate…
|
-
|
CVE-2020-16216
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210470
|
5.9 |
MEDIUM
Network
|
bluetooth
|
bluetooth_core_specification
|
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated …
|
CWE-287
Improper Authentication
|
CVE-2020-15802
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|