Vulnerabilities > Onepeloton

DATE CVE VULNERABILITY TITLE RISK
2021-10-25 CVE-2021-40526 Incorrect Calculation of Buffer Size vulnerability in Onepeloton Ttr01 Firmware Ptv55G
Incorrect calculation of buffer size vulnerability in Peleton TTR01 up to and including PTV55G allows a remote attacker to trigger a Denial of Service attack through the GymKit daemon process by exploiting a heap overflow in the network server handling the Apple GymKit communication.
network
low complexity
onepeloton CWE-131
5.3
2021-10-25 CVE-2021-40527 Cleartext Storage of Sensitive Information vulnerability in Onepeloton Peloton 1.7.22
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application.
network
low complexity
onepeloton CWE-312
7.5
2021-06-15 CVE-2021-33887 Insufficient Verification of Data Authenticity vulnerability in Onepeloton Ttr01 Firmware Ptv55G
Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot into a modified kernel/ramdisk without unlocking the bootloader.
low complexity
onepeloton CWE-345
6.8