Product:

Syncserver_s100_firmware

(Microchip)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 7
Date Id Summary Products Score Patch Annotated
2020-02-17 CVE-2020-9034 Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users. Syncserver_s100_firmware, Syncserver_s200_firmware, Syncserver_s250_firmware, Syncserver_s300_firmware, Syncserver_s350_firmware 7.5
2020-02-17 CVE-2020-9033 Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php. Syncserver_s100_firmware, Syncserver_s200_firmware, Syncserver_s250_firmware, Syncserver_s300_firmware, Syncserver_s350_firmware N/A
2020-02-17 CVE-2020-9032 Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php. Syncserver_s100_firmware, Syncserver_s200_firmware, Syncserver_s250_firmware, Syncserver_s300_firmware, Syncserver_s350_firmware N/A
2020-02-17 CVE-2020-9031 Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php. Syncserver_s100_firmware, Syncserver_s200_firmware, Syncserver_s250_firmware, Syncserver_s300_firmware, Syncserver_s350_firmware N/A
2020-02-17 CVE-2020-9030 Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php. Syncserver_s100_firmware, Syncserver_s200_firmware, Syncserver_s250_firmware, Syncserver_s300_firmware, Syncserver_s350_firmware N/A
2020-02-17 CVE-2020-9029 Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php. Syncserver_s100_firmware, Syncserver_s200_firmware, Syncserver_s250_firmware, Syncserver_s300_firmware, Syncserver_s350_firmware N/A
2020-02-17 CVE-2020-9028 Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user). Syncserver_s100_firmware, Syncserver_s200_firmware, Syncserver_s250_firmware, Syncserver_s300_firmware, Syncserver_s350_firmware N/A