LiveActive security incident?Get immediate response
CVE archive

March 2020

Browse CVE records published in March 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1453 matching CVEs · Page 6 of 30.

Unknown · CVSS Not scored

CVE-2020-36144: Redash 8.0.0 is affected by LDAP Injection.

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.

Published Mar 18, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-35521: A flaw was found in libtiff.

A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.

Published Mar 9, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-35358: DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.

Published Mar 15, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-35137: The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communica...

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in com/mobileiron/registration/RegisterActivity.java and can be used for api/v1/gateway/customers/servers requests. NOTE: Vendor states that this is an opt-in feature to the product - it is not enabled by default and customers cannot enable it without an explicit email to support. At this time, they do not plan change to make any changes to this feature.

Published Mar 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-35138: The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to en...

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in the com/mobileiron/common/utils/C4928m.java file. NOTE: It has been asserted that there is no causality or connection between credential encryption and the MiTM attack

Published Mar 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-28952: An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0.

An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: "01030507090b0d0f00020406080a0c0d" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.

Published Mar 9, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-28899: The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which all...

The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.

Published Mar 16, 2021 · Updated Aug 4, 2024