CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-15043

    Last Modified: 21 Nov 2024

    iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2018-6446

    Last Modified: 21 Nov 2024

    A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-15069

    Last Modified: 7 Nov 2025

    Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

    Published: 29 Jun 2020
    5.3
    Medium

    CVE-2020-13896

    Last Modified: 21 Nov 2024

    The web interface of Maipu MP1800X-50 7.5.3.14(R) devices allows remote attackers to obtain sensitive information via the form/formDeviceVerGet URI, such as system id, hardware model, hardware version, bootloader version, software version, software image file, compilation time, and system uptime. This is similar to CVE-2019-1653.

    Published: 29 Jun 2020
    8.8
    High

    CVE-2020-14414

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary payload (any system commands) that contains shell metacharacters via a POST request with a pw parameter. (This can also be exploited via CSRF.)

    Published: 29 Jun 2020
    6.1
    Medium

    CVE-2020-14413

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.

    Published: 29 Jun 2020
    8.8
    High

    CVE-2020-14412

    Last Modified: 21 Nov 2024

    NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary payload (any system commands) that contains shell metacharacters via a POST request with a psw parameter. (This can also be exploited via CSRF.)

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-14072

    Last Modified: 21 Nov 2024

    An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts.

    Published: 29 Jun 2020
    6.1
    Medium

    CVE-2020-14071

    Last Modified: 21 Nov 2024

    An issue was discovered in MK-AUTH 19.01. XSS vulnerabilities in admin and client scripts allow an attacker to execute arbitrary JavaScript code.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-14070

    Last Modified: 21 Nov 2024

    An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/executar_login.php result in admin access.

    Published: 29 Jun 2020
    6.8
    Medium

    CVE-2020-14069

    Last Modified: 21 Nov 2024

    An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-14068

    Last Modified: 21 Nov 2024

    An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and gain client privileges via SQL injection in central/executar_login.php.

    Published: 29 Jun 2020
    —
    Unknown

    CVE-2020-15356

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Jun 2020
    —
    Unknown

    CVE-2020-15355

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Jun 2020
    —
    Unknown

    CVE-2020-15354

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-15362

    Last Modified: 21 Nov 2024

    wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-15324

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-15323

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-15322

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-15321

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-15320

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15319

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15318

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15317

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.

    Published: 29 Jun 2020
    10
    Critical

    CVE-2020-2021

    Last Modified: 4 Nov 2025

    When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. This issue affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue does not affect PAN-OS 7.1. This issue cannot be exploited if SAML is not used for authentication. This issue cannot be exploited if the 'Validate Identity Provider Certificate' option is enabled (checked) in the SAML Identity Provider Server Profile. Resources that can be protected by SAML-based single sign-on (SSO) authentication are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces, Prisma Access In the case of GlobalProtect Gateways, GlobalProtect Portal, Clientless VPN, Captive Portal, and Prisma Access, an unauthenticated attacker with network access to the affected servers can gain access to protected resources if allowed by configured authentication and Security policies. There is no impact on the integrity and availability of the gateway, portal or VPN server. An attacker cannot inspect or tamper with sessions of regular users. In the worst case, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). In the case of PAN-OS and Panorama web interfaces, this issue allows an unauthenticated attacker with network access to the PAN-OS or Panorama web interfaces to log in as an administrator and perform administrative actions. In the worst-case scenario, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). If the web interfaces are only accessible to a restricted management network, then the issue is lowered to a CVSS Base Score of 9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Palo Alto Networks is not aware of any malicious attempts to exploit this vulnerability.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15316

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15315

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15314

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15313

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.

    Published: 29 Jun 2020
    5.9
    Medium

    CVE-2020-15312

    Last Modified: 21 Nov 2024

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.

    Published: 29 Jun 2020
    6.5
    Medium

    CVE-2020-8573

    Last Modified: 21 Nov 2024

    The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should be changed during the initial node setup. During upgrades to Element 11.8 and 12.0 or the Compute Firmware Bundle 12.2.92 the BMC account password on the H610C, H615C and H610S platforms is reset to the default documented value which could allow remote attackers to cause a Denial of Service (DoS).

    Published: 29 Jun 2020
    5.4
    Medium

    CVE-2020-4557

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183611.

    Published: 29 Jun 2020
    4.3
    Medium

    CVE-2019-18252

    Last Modified: 21 Nov 2024

    BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials used for connecting to the BIOTRONIK Remote Communication infrastructure.

    Published: 29 Jun 2020
    4.3
    Medium

    CVE-2019-18248

    Last Modified: 21 Nov 2024

    BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credentials for connecting to the BIOTRONIK Remote Communication infrastructure.

    Published: 29 Jun 2020
    4.3
    Medium

    CVE-2019-18246

    Last Modified: 21 Nov 2024

    BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.

    Published: 29 Jun 2020
    4.6
    Medium

    CVE-2019-18256

    Last Modified: 21 Nov 2024

    BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.

    Published: 29 Jun 2020
    4.6
    Medium

    CVE-2019-18254

    Last Modified: 21 Nov 2024

    BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with.

    Published: 29 Jun 2020
    6.1
    Medium

    CVE-2020-12012

    Last Modified: 21 Nov 2024

    Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13, and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 have hard-coded administrative account credentials for the ExactaMix application. Successful exploitation of this vulnerability may allow an attacker with physical access to gain unauthorized access to view/update system configuration or data. This could impact confidentiality and integrity of the system and risk exposure of sensitive information including PHI.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-12016

    Last Modified: 21 Nov 2024

    Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 have hard-coded administrative account credentials for the ExactaMix operating system. Successful exploitation of this vulnerability may allow an attacker who has gained unauthorized access to system resources, including access to execute software or to view/update files, directories, or system configuration. This could allow an attacker with network access to view sensitive data including PHI.

    Published: 29 Jun 2020
    7.5
    High

    CVE-2020-12008

    Last Modified: 21 Nov 2024

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network access to view sensitive data including PHI.

    Published: 29 Jun 2020
    9.1
    Critical

    CVE-2020-12032

    Last Modified: 21 Nov 2024

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including PHI.

    Published: 29 Jun 2020
    6.1
    Medium

    CVE-2020-12020

    Last Modified: 21 Nov 2024

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application startup script. Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.

    Published: 29 Jun 2020
    6.1
    Medium

    CVE-2020-12024

    Last Modified: 21 Nov 2024

    Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to the USB interface from an unauthorized user with physical access. Successful exploitation of this vulnerability may allow an attacker with physical access to the system the ability to load an unauthorized payload or unauthorized access to the hard drive by booting a live USB OS. This could impact confidentiality and integrity of the system and risk exposure of sensitive information including PHI.

    Published: 29 Jun 2020
    7.5
    High

    CVE-2020-12036

    Last Modified: 21 Nov 2024

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An attacker could observe sensitive data sent from the device.

    Published: 29 Jun 2020
    4.9
    Medium

    CVE-2020-12035

    Last Modified: 21 Nov 2024

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provides access to biomedical information, device settings, calibration settings, and network configuration. This could allow an attacker to modify device settings and calibration.

    Published: 29 Jun 2020
    7.5
    High

    CVE-2020-12037

    Last Modified: 21 Nov 2024

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An attacker could observe sensitive data sent from the device.

    Published: 29 Jun 2020
    7.5
    High

    CVE-2020-12048

    Last Modified: 21 Nov 2024

    Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.

    Published: 29 Jun 2020
    9.8
    Critical

    CVE-2020-12040

    Last Modified: 21 Nov 2024

    Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow an attacker that has circumvented network security measures to view sensitive non-private data or to perform a man-in-the-middle attack.

    Published: 29 Jun 2020
    2.4
    Low

    CVE-2020-12039

    Last Modified: 21 Nov 2024

    Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide access to biomedical menus including device settings, view calibration values, network configuration of Sigma Spectrum WBM if installed.

    Published: 29 Jun 2020
    9.4
    Critical

    CVE-2020-12041

    Last Modified: 21 Nov 2024

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary configuration changes to network settings are removed upon reboot.

    Published: 29 Jun 2020