Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-28931 | Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthe… | High (8.8) | 2020-12-16 | Environment Specific |
| CVE-2020-28930 | A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSO… | Medium (5.4) | 2020-12-16 | Environment Specific |
| CVE-2020-28929 | Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated a… | Critical (9.8) | 2020-12-16 | Environment Specific |
| CVE-2020-7781 | This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The fol… | Critical (9.8) | 2020-12-16 | Environment Specific |
| CVE-2020-7837 | An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReport… | High (7.5) | 2020-12-16 | Environment Specific |