Vulnerabilities > HCC Embedded > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-08-19 CVE-2020-35683 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in HCC Nichestack 3.0.
network
low complexity
hcc-embedded siemens CWE-125
5.0
2021-08-19 CVE-2020-35684 Improper Input Validation vulnerability in multiple products
An issue was discovered in HCC Nichestack 3.0.
network
low complexity
hcc-embedded siemens CWE-20
5.0
2021-08-19 CVE-2020-35685 Use of Insufficiently Random Values vulnerability in multiple products
An issue was discovered in HCC Nichestack 3.0.
network
low complexity
hcc-embedded siemens CWE-330
6.4
2021-08-19 CVE-2021-27565 Infinite Loop vulnerability in Hcc-Embedded Nichestack
The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP request such as OPTIONS.
network
low complexity
hcc-embedded CWE-835
5.0
2021-08-19 CVE-2021-31401 Improper Input Validation vulnerability in multiple products
An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1.
network
low complexity
hcc-embedded siemens CWE-20
5.0
2021-08-19 CVE-2021-31227 Out-of-bounds Write vulnerability in Hcc-Embedded Nichestack
An issue was discovered in HCC embedded InterNiche 4.0.1.
network
low complexity
hcc-embedded CWE-787
5.0
2021-08-19 CVE-2021-31228 Use of Insufficiently Random Values vulnerability in Hcc-Embedded Nichestack 3.0
An issue was discovered in HCC embedded InterNiche 4.0.1.
network
low complexity
hcc-embedded CWE-330
5.0
2021-08-19 CVE-2021-31400 Infinite Loop vulnerability in Hcc-Embedded Nichestack
An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1.
network
low complexity
hcc-embedded CWE-835
5.0
2021-08-18 CVE-2020-25767 Out-of-bounds Read vulnerability in Hcc-Embedded Nichestack Ipv4 4.1
An issue was discovered in HCC Embedded NicheStack IPv4 4.1.
network
low complexity
hcc-embedded CWE-125
5.0
2021-08-18 CVE-2020-25926 Insufficient Entropy vulnerability in Hcc-Embedded Nichestack Tcp/Ip 4.0.1
The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id.
network
low complexity
hcc-embedded CWE-331
5.0