CVE Vulnerabilities in 2020

39 documented vulnerabilities published in 2020.

Other years: 2026 2025 2024 2023 2022 2021

Top Affected Vendors in 2020

All CVEs from 2020

CVE-2020-7549
5.3 medium

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause denial of HTTP and FTP se

Schneider-Electric Modicon M340 Bmxp341000 Firmware Dec 11, 2020
CVE-2020-28220
6.8 medium

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the w

Schneider-Electric Modicon M258 Firmware Dec 11, 2020
CVE-2020-28214
5.5 medium

A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique such as rainbow tables, effectively disabling the protection that an unpredictabl

Schneider-Electric Modicon M221 Firmware Dec 11, 2020
CVE-2020-1971
5.9 medium

The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrect

Openssl Openssl Dec 8, 2020
CVE-2020-29372
4.7 medium

An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.

Linux Linux Kernel Nov 28, 2020
CVE-2020-7568
4.3 medium

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all references, all versions) that could allow non sensitive information disclosure when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 con

Schneider-Electric Modicon M221 Firmware Nov 19, 2020
CVE-2020-7567
5.7 medium

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke th

Schneider-Electric Modicon M221 Firmware Nov 19, 2020
CVE-2020-7566
7.3 high

A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

Schneider-Electric Modicon M221 Firmware Nov 19, 2020
CVE-2020-7565
7.3 high

A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

Schneider-Electric Modicon M221 Firmware Nov 19, 2020
CVE-2020-28209
7.0 high

A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent s

Schneider-Electric Enterprise Server Installer Nov 19, 2020
CVE-2020-28210
6.1 medium

A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.

Schneider-Electric Ecostruxure Building Operation Nov 19, 2020
CVE-2020-28941
5.5 medium

An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more

Linux Linux Kernel Nov 19, 2020
CVE-2020-13799
6.8 medium

Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for storage device interfaces, including all versions of eMMC, UFS, and NVMe. The RPMB protocol is specified by industry standards bodies and is implemented

Westerndigital Inand Cl Em132 Firmware Nov 18, 2020
CVE-2020-7564
8.8 high

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-7563
8.8 high

A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-7562
8.1 high

A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file o

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-15783
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a Denial-of-Service on p

Siemens Sinumerik 840D Sl Firmware Nov 12, 2020
CVE-2020-28271
9.8 critical

Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

Sharpred Deephas Nov 12, 2020
CVE-2020-17091
7.8 high

Microsoft Teams Remote Code Execution Vulnerability

Microsoft Teams Nov 11, 2020
CVE-2020-17003
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

Microsoft 3D Viewer Oct 16, 2020
CVE-2020-16918
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

Microsoft 365 Apps Oct 16, 2020
CVE-2020-15791
6.5 medium

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010 (All versions), SINUMERIK 840D sl (All versions). The authentication protocol b

Siemens Simatic S7-300 Cpu 312 Firmware Sep 9, 2020
CVE-2020-15786
9.8 critical

A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <=

Siemens Simatic Hmi Basic Panels 2Nd Generation Firmware Sep 9, 2020
CVE-2020-1574
5.5 medium

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code. Exploitation of the vulnerability requires that a program process a specially crafted image

Microsoft Windows 10 Aug 17, 2020