|
210821
|
8.8 |
HIGH
Network
|
vfairs
|
vfairs
|
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
|
CWE-89
SQL Injection
|
CVE-2020-26677
|
2024-11-21 14:20 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210822
|
8.1 |
HIGH
Adjacent
|
bluetooth
|
mesh_profile
|
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without posse…
|
CWE-863
Incorrect Authorization
|
CVE-2020-26560
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210823
|
8.8 |
HIGH
Adjacent
|
bluetooth
|
mesh_profile
|
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s …
|
CWE-863
Incorrect Authorization
|
CVE-2020-26559
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210824
|
4.2 |
MEDIUM
Adjacent
|
bluetooth fedoraproject debian linux intel
|
bluetooth_core_specification fedora debian_linux linux_kernel ax210_firmware ax201_firmware ax200_firmware ac_9560_firmware ac_9462_firmware ac_9461_firmware ac_9260_fir…
|
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authe…
|
CWE-287
Improper Authentication
|
CVE-2020-26558
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210825
|
7.5 |
HIGH
Adjacent
|
bluetooth
|
mesh_profile
|
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute…
|
CWE-287
Improper Authentication
|
CVE-2020-26557
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210826
|
7.5 |
HIGH
Adjacent
|
bluetooth
|
mesh_profile bluetooth_core_specification
|
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-26556
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210827
|
5.4 |
MEDIUM
Adjacent
|
bluetooth fedoraproject intel
|
bluetooth_core_specification fedora ax210_firmware ax201_firmware ax200_firmware ac_9560_firmware ac_9462_firmware ac_9461_firmware ac_9260_firmware ac_8265_firmware ac_…
|
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing witho…
|
CWE-863
Incorrect Authorization
|
CVE-2020-26555
|
2024-11-21 14:20 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210828
|
5.7 |
MEDIUM
Physics
|
nordicsemi
|
nrf52840_firmware
|
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-27211
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210829
|
7.0 |
HIGH
Local
|
st
|
stm32cubel4_firmware
|
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (l…
|
CWE-74
Injection
|
CVE-2020-27212
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210830
|
6.8 |
MEDIUM
Physics
|
solokeys nitrokey
|
solo_firmware somu_firmware fido2_firmware
|
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-27208
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|