Microchip / Syncserver S250 Firmware
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-9028 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User C… | MEDIUM | 6.1 | Feb 17, 2020 |
| CVE-2020-9029 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messa… | MEDIUM | 6.5 | Feb 17, 2020 |
| CVE-2020-9030 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the s… | MEDIUM | 6.5 | Feb 17, 2020 |
| CVE-2020-9031 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemo… | MEDIUM | 6.5 | Feb 17, 2020 |
| CVE-2020-9032 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernl… | MEDIUM | 6.5 | Feb 17, 2020 |
| CVE-2020-9033 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authl… | MEDIUM | 6.5 | Feb 17, 2020 |
| CVE-2020-9034 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated crea… | HIGH | 7.5 | Feb 17, 2020 |
Showing 1 to 7 of 7 CVEs