Vulnerabilities > Omninova

DATE CVE VULNERABILITY TITLE RISK
2018-02-09 CVE-2018-6827 Improper Certificate Validation vulnerability in Omninova Vobot Firmware
VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information, and consequently execute arbitrary code, via a crafted certificate, as demonstrated by leveraging a hardcoded --no-check-certificate Wget option.
network
high complexity
omninova CWE-295
8.1
2018-02-09 CVE-2018-6826 Unspecified vulnerability in Omninova Vobot Firmware
An issue was discovered on VOBOT CLOCK before 0.99.30 devices.
network
high complexity
omninova
7.5
2018-02-09 CVE-2018-6825 Use of Hard-coded Credentials vulnerability in Omninova Vobot Firmware
An issue was discovered on VOBOT CLOCK before 0.99.30 devices.
network
low complexity
omninova CWE-798
critical
9.8