|
196011
|
3.1 |
LOW
Network
|
kubernetes
|
kubernetes
|
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Servi…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-8562
|
2024-11-21 14:39 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196012
|
6.5 |
MEDIUM
Adjacent
|
aeotec samsung zooz silabs
|
zw090-a sth-eth-200 zst10 uzb-7 700_series_firmware 500_series_firmware
|
Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung …
|
NVD-CWE-noinfo
|
CVE-2020-9061
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196013
|
6.5 |
MEDIUM
Adjacent
|
silabs aeotec zooz fibaro
|
500_series_firmware zw090-a zst10 zen20 zen25 fgwpb-111
|
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9060
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196014
|
6.5 |
MEDIUM
Adjacent
|
silabs schlage
|
500_series_firmware be468
|
Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example, the Schlage BE468 v…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-9059
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196015
|
8.1 |
HIGH
Adjacent
|
silabs jasco dome linear
|
500_series_firmware zw4201 dm501 lb60z-1
|
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 vers…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-9058
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196016
|
8.8 |
HIGH
Adjacent
|
linear silabs
|
wapirz-1 wadwaz-1 100_series_firmware 200_series_firmware 300_series_firmware
|
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerab…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-9057
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196017
|
7.1 |
HIGH
Local
|
parallels
|
remote_application_server
|
Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confid…
|
NVD-CWE-Other
|
CVE-2020-8968
|
2024-11-21 14:39 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196018
|
7.8 |
HIGH
Local
|
intel
|
thunderbolt_non-dch_driver
|
Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via loca…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8741
|
2024-11-21 14:39 |
2021-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196019
|
4.1 |
MEDIUM
Network
|
kubernetes
|
kubernetes
|
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver re…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-8561
|
2024-11-21 14:39 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196020
|
7.5 |
HIGH
Network
|
iportalis
|
iportalis_control_portal
|
An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Admi…
|
CWE-20
Improper Input Validation
|
CVE-2020-9002
|
2024-11-21 14:39 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|