Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-25190 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials … | High (7.5) | 2020-12-23 | Environment Specific |
| CVE-2020-25153 | The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have stron… | Critical (9.8) | 2020-12-23 | Environment Specific |
| CVE-2020-29583 | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The … | Critical (9.8) | 2020-12-22 | Environment Specific |
| CVE-2020-27336 | An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a … | Low (3.7) | 2020-12-22 | Environment Specific |
| CVE-2020-24679 | A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this fl… | High (7.5) | 2020-12-22 | Environment Specific |