|
209251
|
9.8 |
CRITICAL
Network
|
nagios
|
nagios_xi
|
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was …
|
NVD-CWE-noinfo
|
CVE-2020-15903
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209252
|
5.3 |
MEDIUM
Network
|
siemens
|
spectrum_power_4
|
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.
|
CWE-200
Information Exposure
|
CVE-2020-15790
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209253
|
9.8 |
CRITICAL
Network
|
siemens
|
simatic_hmi_united_comfort_panels_firmware
|
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be trunc…
|
-
|
CVE-2020-15787
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209254
|
5.3 |
MEDIUM
Network
|
siemens
|
siveillance_video_client
|
A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the…
|
-
|
CVE-2020-15785
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209255
|
5.3 |
MEDIUM
Network
|
siemens
|
spectrum_power_4
|
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15784
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209256
|
6.5 |
MEDIUM
Adjacent
|
philips
|
performancebridge_focal_point patient_information_center_ix intellivue_mp2-mp90_firmware intellivue_mx100_firmware intellivue_mx400_firmware intellivue_mx850_firmware intellivue_x2_…
|
In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750,
MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior,
the product receives input or data but does not validate…
|
-
|
CVE-2020-16216
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209257
|
5.9 |
MEDIUM
Network
|
bluetooth
|
bluetooth_core_specification
|
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated …
|
CWE-287
Improper Authentication
|
CVE-2020-15802
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209258
|
6.4 |
MEDIUM
Adjacent
|
philips
|
performancebridge_focal_point patient_information_center_ix intellivue_mp2-mp90_firmware intellivue_mx100_firmware intellivue_mx400_firmware intellivue_mx850_firmware intellivue_x2_…
|
In Patient Information Center iX (PICiX) Versions C.02 and C.03,
PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors
MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions…
|
-
|
CVE-2020-16228
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209259
|
6.5 |
MEDIUM
Adjacent
|
siemens
|
simatic_s7-300_cpu_312_firmware simatic_s7-300_cpu_314_firmware simatic_s7-300_cpu_315-2_dp_firmware simatic_s7-300_cpu_315-2_pn_firmware simatic_s7-300_cpu_317-2_pn_firmware simatic_s…
|
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMAT…
|
-
|
CVE-2020-15791
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209260
|
8.1 |
HIGH
Network
|
siemens
|
polarion_subversion_webclient
|
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into a…
|
CWE-352
Origin Validation Error
|
CVE-2020-15789
|
2024-11-21 14:06 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|