Show filters
71 Total Results
Displaying 61-70 of 71
Sort by:
Attacker Value
Unknown
CVE-2019-18254
Disclosure Date: June 29, 2020 (last updated February 21, 2025)
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with.
0
Attacker Value
Unknown
CVE-2020-12032
Disclosure Date: June 29, 2020 (last updated February 21, 2025)
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including PHI.
0
Attacker Value
Unknown
CVE-2020-10273
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.
0
Attacker Value
Unknown
CVE-2020-4233
Disclosure Date: May 27, 2020 (last updated February 21, 2025)
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 175360.
0
Attacker Value
Unknown
CVE-2020-12801
Disclosure Date: May 18, 2020 (last updated February 21, 2025)
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format of the recovered document was not LibreOffice's default ODF file format, then affected versions of LibreOffice default that subsequent saves of the document are unencrypted. This may lead to a user accidentally saving a MSOffice file format document unencrypted while believing it to be encrypted. This issue affects: LibreOffice 6-3 series versions prior to 6.3.6; 6-4 series versions prior to 6.4.3.
0
Attacker Value
Unknown
CVE-2020-12273
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
0
Attacker Value
Unknown
CVE-2020-10267
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software components (URCaps). These files (*.urcaps) are stored under '/root/.urcaps' as plain zip files containing all the logic to add functionality to the UR3, UR5 and UR10 robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property.
0
Attacker Value
Unknown
CVE-2019-19090
Disclosure Date: April 02, 2020 (last updated February 21, 2025)
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
0
Attacker Value
Unknown
CVE-2019-15653
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and password. The username are password values are a double md5 of the plaintext real value, i.e., md5(md5(value)).
0
Attacker Value
Unknown
CVE-2019-4616
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 168644.
0