|
208451
|
8.8 |
HIGH
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27264
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208452
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-i anydana-a dana_diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27258
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208453
|
6.8 |
MEDIUM
Physics
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin ther…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-27256
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208454
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-27276
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208455
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump b…
|
NVD-CWE-noinfo
|
CVE-2020-27272
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208456
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in tra…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27270
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208457
|
6.1 |
MEDIUM
Network
|
eclipse
|
hawkbit
|
In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST reques…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27219
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208458
|
5.4 |
MEDIUM
Network
|
skyworth
|
gn542vf_firmware
|
Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26733
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208459
|
7.5 |
HIGH
Network
|
skyworth
|
gn542vf_boa_firmware
|
SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-26732
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208460
|
8.8 |
HIGH
Network
|
eclipse
|
hono
|
The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a…
|
CWE-862
Missing Authorization
|
CVE-2020-27220
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|