Vulnerabilities > Raspberrypi

DATE CVE VULNERABILITY TITLE RISK
2021-12-07 CVE-2021-38759 Insecure Default Initialization of Resource vulnerability in Raspberrypi Raspberry PI OS Lite 5.10
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.
network
low complexity
raspberrypi CWE-1188
critical
9.8
2021-08-11 CVE-2021-38545 Unspecified vulnerability in Raspberrypi products
Raspberry Pi 3 B+ and 4 B devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack.
network
high complexity
raspberrypi
5.9
2019-04-04 CVE-2018-18068 Exposure of Resource to Wrong Sphere vulnerability in Raspberrypi Raspberry PI 3 Model B+ Firmware
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor debugging.
network
low complexity
raspberrypi CWE-668
critical
9.8