Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-7240 | Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS… | High (8.8) | 2020-01-20 | Environment Specific |
| CVE-2020-7236 | UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section). | Medium (6.1) | 2020-01-19 | Environment Specific |
| CVE-2020-7235 | UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title). | Medium (6.1) | 2020-01-19 | Environment Specific |
| CVE-2020-7234 | Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wir… | Medium (4.8) | 2020-01-19 | Environment Specific |
| CVE-2020-7233 | KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Lo… | Critical (9.8) | 2020-01-19 | Environment Specific |