Vulnerabilities > Lindy International

DATE CVE VULNERABILITY TITLE RISK
2020-08-07 CVE-2020-15061 Improper Input Validation vulnerability in Lindy-International 42633 Firmware 2.078.000
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
low complexity
lindy-international CWE-20
6.1
2020-08-07 CVE-2020-15060 Cross-site Scripting vulnerability in Lindy-International 42633 Firmware 2.078.000
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
2.3
2020-08-07 CVE-2020-15059 Improper Authentication vulnerability in Lindy-International 42633 Firmware 2.078.000
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
low complexity
lindy-international CWE-287
8.3
2020-08-07 CVE-2020-15058 Insufficiently Protected Credentials vulnerability in Lindy-International 42633 Firmware 2.078.000
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
low complexity
lindy-international CWE-522
3.3