Show filters
123 Total Results
Displaying 51-60 of 123
Sort by:
Attacker Value
Unknown
CVE-2021-37160
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.
0
Attacker Value
Unknown
CVE-2021-37167
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.
0
Attacker Value
Unknown
CVE-2021-37164
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer overflow.
0
Attacker Value
Unknown
CVE-2021-37161
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution.
0
Attacker Value
Unknown
CVE-2021-37163
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.
0
Attacker Value
Unknown
CVE-2021-37166
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.
0
Attacker Value
Unknown
CVE-2021-37162
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution.
0
Attacker Value
Unknown
CVE-2021-37165
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.
0
Attacker Value
Unknown
CVE-2020-28074
Disclosure Date: December 23, 2020 (last updated February 22, 2025)
SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.
0
Attacker Value
Unknown
CVE-2020-25175
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
0