Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2020
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
CVSS Score
5.4
EPSS Score
0.002
Published
2020-08-26
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
CVSS Score
5.4
EPSS Score
0.002
Published
2020-08-26
In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, BIG-IP ASM Configuration utility CSRF protection token can be reused multiple times.
CVSS Score
3.1
EPSS Score
0.0
Published
2020-08-26
An issue was discovered in HiveMQ Broker Control Center 4.3.2. A crafted clientid parameter in an MQTT packet (sent to the Broker) is reflected in the client section of the management console. The attacker's JavaScript is loaded in a browser, which can lead to theft of the session and cookie of the administrator's account of the Broker.
CVSS Score
5.4
EPSS Score
0.003
Published
2020-08-26
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.
CVSS Score
7.8
EPSS Score
0.0
Published
2020-08-26
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.
CVSS Score
6.8
EPSS Score
0.0
Published
2020-08-26
An issue was discovered on Dr Trust ECG Pen 2.00.08 devices. Because the Bluetooth LE support is implemented without a requirement for pairing or security, any attacker can access the GATT server of the device and can sniff the data being broadcasted while a measurement is being done. Also, saved data can also be extracted over a Bluetooth connection. In addition, an attacker can launch a man-in-the-middle attack against data integrity.
CVSS Score
6.5
EPSS Score
0.002
Published
2020-08-26
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail.
CVSS Score
5.9
EPSS Score
0.003
Published
2020-08-26
in BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, Syn flood causes large number of MCPD context messages destined to secondary blades consuming memory leading to MCPD failure. This issue affects only VIPRION hosts with two or more blades installed. Single-blade VIPRION hosts are not affected.
CVSS Score
7.5
EPSS Score
0.006
Published
2020-08-26
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, undisclosed internally generated UDP traffic may cause the Traffic Management Microkernel (TMM) to restart under some circumstances.
CVSS Score
7.5
EPSS Score
0.006
Published
2020-08-26


Contact Us

Shodan ® - All rights reserved