Lucene search

K

One Firmware Security Vulnerabilities

cve
cve

CVE-2019-14353

On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be ...

4.2CVSS

4.3AI Score

0.001EPSS

2019-08-08 07:15 PM
27
cve
cve

CVE-2020-15418

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML Externa...

7.5CVSS

7.3AI Score

0.024EPSS

2020-07-28 06:15 PM
36
cve
cve

CVE-2020-15419

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Reporter_ImportLicense class. Due to the improper restriction of...

7.5CVSS

7.3AI Score

0.024EPSS

2020-07-28 06:15 PM
37
cve
cve

CVE-2020-9285

Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.

6.8CVSS

6.5AI Score

0.001EPSS

2022-10-20 05:15 PM
26
6
cve
cve

CVE-2023-27352

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of the SMB directory query command. The issue result...

8.8CVSS

8.9AI Score

0.001EPSS

2023-04-20 10:15 PM
20
cve
cve

CVE-2023-27353

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the msprox endpoint. The issue results from the lack of pro...

6.5CVSS

5.8AI Score

0.001EPSS

2023-04-20 10:15 PM
18
cve
cve

CVE-2023-27354

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of the SMB directory query command. The issu...

6.5CVSS

6.1AI Score

0.001EPSS

2023-04-20 10:15 PM
15
cve
cve

CVE-2023-27355

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MPEG-TS parser. The issue results from the lack of proper valid...

8.8CVSS

8.8AI Score

0.001EPSS

2023-04-20 10:15 PM
27