Show filters
112 Total Results
Displaying 1-10 of 112
Sort by:
Attacker Value
Unknown

CVE-2018-19944

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)
Attacker Value
Unknown

CVE-2020-11718

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.
Attacker Value
Unknown

CVE-2020-35584

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.
Attacker Value
Unknown

CVE-2020-13528

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-14248

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Attacker Value
Unknown

CVE-2020-27586

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
Attacker Value
Unknown

CVE-2020-29380

Disclosure Date: November 29, 2020 (last updated February 22, 2025)
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker can intercept passwords sent in cleartext and conduct a man-in-the-middle attack on the management of the appliance.
Attacker Value
Unknown

CVE-2020-29055

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. By default, the appliance can be managed remotely only with HTTP, telnet, and SNMP. It doesn't support SSL/TLS for HTTP or SSH. An attacker can intercept passwords sent in cleartext and conduct man-in-the-middle attacks on the management of the appliance.
Attacker Value
Unknown

CVE-2020-25988

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent.
Attacker Value
Unknown

CVE-2020-27554

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the camera device.