Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-16257 | Winston 1.5.4 devices are vulnerable to command injection via the API. | Critical (9.8) | 2020-10-28 | Environment Specific |
| CVE-2020-22552 | The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-u… | High (7.5) | 2020-10-28 | Environment Specific |
| CVE-2020-8263 | A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduc… | Medium (5.4) | 2020-10-28 | Environment Specific |
| CVE-2020-8262 | A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Si… | Medium (6.1) | 2020-10-28 | Environment Specific |
| CVE-2020-8261 | A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection. | Medium (4.3) | 2020-10-28 | Environment Specific |