Vulnerabilities > Digitus

DATE CVE VULNERABILITY TITLE RISK
2020-08-07 CVE-2020-15065 Improper Input Validation vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values.
low complexity
digitus CWE-20
6.1
2020-08-07 CVE-2020-15064 Cross-site Scripting vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
2.3
2020-08-07 CVE-2020-15063 Improper Authentication vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
low complexity
digitus CWE-287
8.3
2020-08-07 CVE-2020-15062 Insufficiently Protected Credentials vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
low complexity
digitus CWE-522
3.3