|
211111
|
6.5 |
MEDIUM
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.
|
CWE-287
Improper Authentication
|
CVE-2020-27558
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211112
|
5.5 |
MEDIUM
Local
|
basetech
|
ge-131_bt-1837836_firmware
|
Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files contai…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27557
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211113
|
5.3 |
MEDIUM
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27556
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211114
|
9.8 |
CRITICAL
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-27555
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211115
|
7.5 |
HIGH
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the …
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-27554
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211116
|
7.5 |
HIGH
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoot /etc“. This allows an attacker with network access to the web-server to downl…
|
CWE-22
Path Traversal
|
CVE-2020-27553
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211117
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-27486
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211118
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectI…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-27485
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211119
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27484
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211120
|
9.9 |
CRITICAL
Network
|
garmin
|
forerunner_235_firmware
|
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectI…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-27483
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|