Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2014-9382 | Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation | Medium (6.5) | 2020-01-13 | Environment Specific |
| CVE-2014-5381 | Grand MA 300 allows a brute-force attack on the PIN. | Critical (9.8) | 2020-01-13 | Environment Specific |
| CVE-2014-5380 | Grand MA 300 allows retrieval of the access PIN from sniffed data. | High (7.5) | 2020-01-13 | Environment Specific |
| CVE-2020-6848 | Axper Vision II 4 devices allow XSS via the DEVICE_NAME (aka Device Name) parameter to the configWebParams.cgi URI. | Medium (6.1) | 2020-01-13 | Environment Specific |
| CVE-2019-20377 | TopList before 2019-09-03 allows XSS via a title. | Medium (6.1) | 2020-01-11 | Environment Specific |