|
209401
|
8.4 |
HIGH
Local
|
siemens
|
logo\!_soft_comfort
|
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking.
Successful exploitation by a local…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-25244
|
2024-11-21 14:17 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209402
|
5.1 |
MEDIUM
Local
|
siemens
|
logo\!_soft_comfort
|
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importing a compromised project file
to the affected software. Chain…
|
-
|
CVE-2020-25243
|
2024-11-21 14:17 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209403
|
9.8 |
CRITICAL
Network
|
grandstream
|
grp2612_firmware grp2612p_firmware grp2612w_firmware grp2613_firmware grp2614_firmware grp2615_firmware grp2616_firmware
|
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-25218
|
2024-11-21 14:17 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209404
|
7.2 |
HIGH
Network
|
grandstream
|
grp2612_firmware grp2612p_firmware grp2612w_firmware grp2613_firmware grp2614_firmware grp2615_firmware grp2616_firmware
|
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
|
CWE-77
Command Injection
|
CVE-2020-25217
|
2024-11-21 14:17 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209405
|
8.6 |
HIGH
Network
|
squid-cache debian fedoraproject netapp
|
squid debian_linux fedora cloud_manager
|
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbi…
|
CWE-20 CWE-444
Improper Input Validation HTTP Request Smuggling
|
CVE-2020-25097
|
2024-11-21 14:17 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209406
|
7.5 |
HIGH
Network
|
siemens
|
simatic_mv440_sr_firmware simatic_mv440_hr_firmware simatic_mv440_ur_firmware simatic_mv420_sr-b_firmware simatic_mv420_sr-p_firmware simatic_mv420_sr-b_body_firmware simatic_mv420_…
|
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-25241
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209407
|
8.8 |
HIGH
Network
|
siemens
|
sinema_remote_connect_server
|
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integr…
|
-
|
CVE-2020-25240
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209408
|
8.8 |
HIGH
Network
|
siemens
|
sinema_remote_connect_server
|
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the…
|
-
|
CVE-2020-25239
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209409
|
5.5 |
MEDIUM
Local
|
siemens
|
logo\!_8_bm_firmware
|
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO!…
|
-
|
CVE-2020-25236
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209410
|
8.8 |
HIGH
Network
|
advantech
|
webaccess\/scada
|
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an adminis…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-25161
|
2024-11-21 14:17 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|