Vulnerabilities (CVE)

Filtered by CWE-757
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38883 2024-08-07 N/A 9.1 CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.
CVE-2024-20069 2024-08-01 N/A 6.5 MEDIUM
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.
CVE-2021-36326 1 Dell 1 Emc Streaming Data Platform 2024-02-04 4.3 MEDIUM 6.5 MEDIUM
Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format.
CVE-2020-16200 1 Philips 1 Clinical Collaboration Platform 2024-02-04 3.3 LOW 6.5 MEDIUM
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.