|
208041
|
7.5 |
HIGH
Adjacent
|
bluetooth
|
mesh_profile bluetooth_core_specification
|
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-26556
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208042
|
5.4 |
MEDIUM
Adjacent
|
bluetooth fedoraproject intel
|
bluetooth_core_specification fedora ax210_firmware ax201_firmware ax200_firmware ac_9560_firmware ac_9462_firmware ac_9461_firmware ac_9260_firmware ac_8265_firmware ac_…
|
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing witho…
|
CWE-863
Incorrect Authorization
|
CVE-2020-26555
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208043
|
5.7 |
MEDIUM
Physics
|
nordicsemi
|
nrf52840_firmware
|
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-27211
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208044
|
7.0 |
HIGH
Local
|
st
|
stm32cubel4_firmware
|
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (l…
|
CWE-74
Injection
|
CVE-2020-27212
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208045
|
6.8 |
MEDIUM
Physics
|
solokeys nitrokey
|
solo_firmware somu_firmware fido2_firmware
|
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-27208
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208046
|
7.5 |
HIGH
Network
|
micro-ecc_project
|
micro-ecc
|
The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversary to extract the private ECC key.
|
NVD-CWE-noinfo
|
CVE-2020-27209
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208047
|
7.5 |
HIGH
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-27185
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208048
|
5.9 |
MEDIUM
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-th…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-27184
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208049
|
7.5 |
HIGH
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-…
|
NVD-CWE-noinfo
|
CVE-2020-27150
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208050
|
6.5 |
MEDIUM
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration chan…
|
NVD-CWE-noinfo
|
CVE-2020-27149
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|