CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-10275

    Last Modified: 21 Nov 2024

    The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-10273

    Last Modified: 21 Nov 2024

    MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.

    Published: 24 Jun 2020
    4.6
    Medium

    CVE-2020-10278

    Last Modified: 21 Nov 2024

    The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.

    Published: 24 Jun 2020
    6.4
    Medium

    CVE-2020-10277

    Last Modified: 21 Nov 2024

    There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-10270

    Last Modified: 21 Nov 2024

    Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. This flaw allows cyber attackers to take control of the robot remotely and make use of the default user interfaces MiR has created, lowering the complexity of attacks and making them available to entry-level attackers. More elaborated attacks can also be established by clearing authentication and sending network requests directly. We have confirmed this flaw in MiR100 and MiR200 but according to the vendor, it might also apply to MiR250, MiR500 and MiR1000.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-10276

    Last Modified: 21 Nov 2024

    The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not affected (thus it is hard to detect before something happens) though the laser scanner configuration can also be affected altering further the safety of the device.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-10271

    Last Modified: 21 Nov 2024

    MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be mitigated by appropriately configuring ROS and/or applying custom patches as appropriate. Currently, the ROS computational graph can be accessed fully from the wired exposed ports. In combination with other flaws such as CVE-2020-10269, the computation graph can also be fetched and interacted from wireless networks. This allows a malicious operator to take control of the ROS logic and correspondingly, the complete robot given that MiR's operations are centered around the framework (ROS).

    Published: 24 Jun 2020
    7.1
    High

    CVE-2020-10274

    Last Modified: 21 Nov 2024

    The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-2020-10273 allows any attacker connected to the robot networks (wired or wireless) to exfiltrate all stored data (e.g. indoor mapping images) and associated metadata from the robot's database.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-10272

    Last Modified: 21 Nov 2024

    MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.

    Published: 24 Jun 2020
    3.2
    Low

    CVE-2020-25743

    Last Modified: 21 Nov 2024

    hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

    Published: 24 Jun 2020
    3.1
    Low

    CVE-2020-15005

    Last Modified: 21 Nov 2024

    In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

    Published: 24 Jun 2020
    3.2
    Low

    CVE-2020-25084

    Last Modified: 21 Nov 2024

    QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.

    Published: 24 Jun 2020
    7.8
    High

    CVE-2020-8177

    Last Modified: 15 Apr 2026

    curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

    Published: 24 Jun 2020
    5
    Medium

    CVE-2020-25085

    Last Modified: 21 Nov 2024

    QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.

    Published: 24 Jun 2020
    3.2
    Low

    CVE-2020-25741

    Last Modified: 21 Nov 2024

    fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.

    Published: 24 Jun 2020
    3.2
    Low

    CVE-2020-25742

    Last Modified: 21 Nov 2024

    pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-8169

    Last Modified: 21 Nov 2024

    curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).

    Published: 24 Jun 2020
    8.8
    High

    CVE-2020-12033

    Last Modified: 21 Nov 2024

    In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.

    Published: 23 Jun 2020
    9
    Critical

    CVE-2020-12021

    Last Modified: 21 Nov 2024

    In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.

    Published: 23 Jun 2020
    7.4
    High

    CVE-2020-5367

    Last Modified: 21 Nov 2024

    Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit.

    Published: 23 Jun 2020
    6.4
    Medium

    CVE-2020-5345

    Last Modified: 21 Nov 2024

    Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics.

    Published: 23 Jun 2020
    8.8
    High

    CVE-2020-13155

    Last Modified: 21 Nov 2024

    clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.

    Published: 23 Jun 2020
    6.5
    Medium

    CVE-2020-13156

    Last Modified: 21 Nov 2024

    modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

    Published: 23 Jun 2020
    6.5
    Medium

    CVE-2020-13157

    Last Modified: 21 Nov 2024

    modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.

    Published: 23 Jun 2020
    5.4
    Medium

    CVE-2020-14073

    Last Modified: 21 Nov 2024

    XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.

    Published: 23 Jun 2020
    7.1
    High

    CVE-2020-14974

    Last Modified: 21 Nov 2024

    The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124.

    Published: 23 Jun 2020
    7.8
    High

    CVE-2020-14975

    Last Modified: 21 Nov 2024

    The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code 0x222124.

    Published: 23 Jun 2020
    5.5
    Medium

    CVE-2020-14976

    Last Modified: 21 Nov 2024

    GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.

    Published: 23 Jun 2020
    8.1
    High

    CVE-2020-14977

    Last Modified: 21 Nov 2024

    An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.

    Published: 23 Jun 2020
    8.1
    High

    CVE-2020-14978

    Last Modified: 21 Nov 2024

    An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.

    Published: 23 Jun 2020
    8.8
    High

    CVE-2020-14298

    Last Modified: 21 Nov 2024

    The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version 1.13.1-108.git4ef4b30.el7, shipped in Red Hat Enterprise Linux 7 Extras. Both earlier and later versions are not affected.

    Published: 23 Jun 2020
    8.8
    High

    CVE-2020-14300

    Last Modified: 21 Nov 2024

    The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of the container. This could lead to compromise of the container host or other containers running on the same container host. This issue only affects a single version of Docker, 1.13.1-108.git4ef4b30, shipped in Red Hat Enterprise Linux 7. Both earlier and later versions are not affected.

    Published: 23 Jun 2020
    5.3
    Medium

    CVE-2020-4188

    Last Modified: 21 Nov 2024

    IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.

    Published: 23 Jun 2020
    5
    Medium

    CVE-2020-11068

    Last Modified: 21 Nov 2024

    In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. This has been fixed in 4.4.4.

    Published: 23 Jun 2020
    5.9
    Medium

    CVE-2020-9438

    Last Modified: 21 Nov 2024

    Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.

    Published: 23 Jun 2020
    7.8
    High

    CVE-2020-14971

    Last Modified: 21 Nov 2024

    Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them. This occurs in settings.php. To exploit this, an attacker would request a backup of limited files via teleporter.php. These are placed into a .tar.gz archive. The attacker then modifies the host parameter in dnsmasq.d files, and then compresses and uploads these files again.

    Published: 23 Jun 2020
    4.8
    Medium

    CVE-2020-14965

    Last Modified: 21 Nov 2024

    On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and change the HTML context of the target pages and stations in the access-control settings via targets_lists_name or hosts_lists_name. The vulnerability can also be exploited through a CSRF, requiring no authentication as an administrator.

    Published: 23 Jun 2020
    5.3
    Medium

    CVE-2020-4028

    Last Modified: 21 Nov 2024

    Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

    Published: 23 Jun 2020
    9.8
    Critical

    CVE-2020-14993

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.

    Published: 23 Jun 2020
    9.8
    Critical

    CVE-2020-14938

    Last Modified: 21 Nov 2024

    An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It copies data from a file into a fixed-size heap-allocated buffer without size verification, leading to a heap-based buffer overflow.

    Published: 23 Jun 2020
    7.8
    High

    CVE-2020-14939

    Last Modified: 21 Nov 2024

    An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.

    Published: 23 Jun 2020
    7.5
    High

    CVE-2020-14940

    Last Modified: 21 Nov 2024

    An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

    Published: 23 Jun 2020
    9.8
    Critical

    CVE-2020-5594

    Last Modified: 21 Nov 2024

    Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vectors.

    Published: 23 Jun 2020
    9.8
    Critical

    CVE-2020-12782

    Last Modified: 21 Nov 2024

    Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.

    Published: 23 Jun 2020
    9.8
    Critical

    CVE-2019-20409

    Last Modified: 21 Nov 2024

    The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.

    Published: 23 Jun 2020
    9.9
    Critical

    CVE-2020-14316

    Last Modified: 21 Nov 2024

    A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful exploitation allows an attacker to assume the privileges of the VM process on the host system. In worst-case scenarios an attacker can read and modify any file on the system where the VMI is running. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 23 Jun 2020
    4.4
    Medium

    CVE-2020-15025

    Last Modified: 21 Nov 2024

    ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

    Published: 23 Jun 2020
    6.8
    Medium

    CVE-2020-15720

    Last Modified: 21 Nov 2024

    In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.

    Published: 23 Jun 2020
    5.4
    Medium

    CVE-2020-14943

    Last Modified: 21 Nov 2024

    The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cross-site scripting (XSS) via Update User Profile.

    Published: 22 Jun 2020
    9.8
    Critical

    CVE-2020-14944

    Last Modified: 21 Nov 2024

    Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

    Published: 22 Jun 2020