CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Mx900_firmware, Mx900, Verix_os, Vx520, P400_firmware, P400, P200_firmware, P200, Vx_820_firmware, Vx_820
2020-10-28
N/A
6.7 MEDIUM
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation.
Mx900_firmware, Mx900, Verix_os, Vx520, P400_firmware, P400, P200_firmware, P200, Vx_820_firmware, Vx_820
2020-10-30
N/A
7.8 HIGH
Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call.
Mx900_firmware, Mx900, Verix_os, Vx520, P400_firmware, P400, P200_firmware, P200, Vx_820_firmware, Vx_820
2020-10-30
N/A
6.6 MEDIUM
Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out).
Mx900_firmware, Mx900, Verix_os, Vx520, P400_firmware, P400, P200_firmware, P200, Vx_820_firmware, Vx_820
2020-10-30
N/A
6.8 MEDIUM
Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation.
Mx900_firmware, Mx900, Verix_os, Vx520, P400_firmware, P400, P200_firmware, P200, Vx_820_firmware, Vx_820
2020-10-28
N/A
5.5 MEDIUM
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages.
Mx900_firmware, Mx900, Verix_os, Vx520, P400_firmware, P400, P200_firmware, P200, Vx_820_firmware, Vx_820
2020-10-30
N/A
7.8 HIGH
Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation.
Mx900_firmware, Mx900, Verix_os, Vx520, P400_firmware, P400, P200_firmware, P200, Vx_820_firmware, Vx_820
2021-07-21
N/A
7 HIGH
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
2020-08-24
N/A
9.8 CRITICAL
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
2019-08-14
N/A
9.8 CRITICAL
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody account.
