Show filters
1,625 Total Results
Displaying 451-460 of 1,625
Sort by:
Attacker Value
Unknown
CVE-2021-35108
Disclosure Date: September 02, 2022 (last updated October 08, 2023)
Improper checking of AP-S lock bit while verifying the secure resource group permissions can lead to non secure read and write access in Snapdragon Connectivity, Snapdragon Mobile
0
Attacker Value
Unknown
CVE-2021-35097
Disclosure Date: September 02, 2022 (last updated October 08, 2023)
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
0
Attacker Value
Unknown
CVE-2022-36385
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device.
0
Attacker Value
Unknown
CVE-2022-38069
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters
0
Attacker Value
Unknown
CVE-2021-4122
Disclosure Date: August 24, 2022 (last updated October 08, 2023)
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
0
Attacker Value
Unknown
CVE-2022-34345
Disclosure Date: August 18, 2022 (last updated October 08, 2023)
Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.
0
Attacker Value
Unknown
CVE-2022-32579
Disclosure Date: August 18, 2022 (last updated October 08, 2023)
Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.
0
Attacker Value
Unknown
CVE-2022-28697
Disclosure Date: August 18, 2022 (last updated October 08, 2023)
Improper access control in firmware for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
0
Attacker Value
Unknown
CVE-2022-38392
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
Certain 5400 RPM hard drives, for laptops and other PCs in approximately 2005 and later, allow physically proximate attackers to cause a denial of service (device malfunction and system crash) via a resonant-frequency attack with the audio signal from the Rhythm Nation music video. A reported product is Seagate STDT4000100 763649053447.
0
Attacker Value
Unknown
CVE-2022-36307
Disclosure Date: August 16, 2022 (last updated October 08, 2023)
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
0