Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2020-35587

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative impact, or instead only facilitates an attack technique
Attacker Value
Unknown

CVE-2020-35586

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).
Attacker Value
Unknown

CVE-2020-35585

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.
Attacker Value
Unknown

CVE-2020-35584

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.
Attacker Value
Unknown

CVE-2020-27523

Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot, which leads to a denial of service.
Attacker Value
Unknown

CVE-2017-12945

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute arbitrary commands as root.