| CVE-2016-2060 |
Command Execution in netd daemon |
Qualcomm |
Jake Valletta |
FireEye blog post |
| CVE-2017-3748 |
Improper access controls in nac_server binary |
Lenovo |
Jake Valletta |
FireEye blog post |
| CVE-2017-3749 |
Local backups enabled in Lenovo Idea Friend application |
Lenovo |
Jake Valletta |
Released with 2017-3748 + 2017-3750 |
| CVE-2017-3750 |
Local backups enabled in Lenovo Security application |
Lenovo |
Jake Valletta |
Released with 2017-3748 + 2017-3749 |
| CVE-2018-18766 |
Elevation of privilege in Call Dispatcher service |
SiteKiosk |
Jake Valletta |
|
| CVE-2019-11509 |
Authenticated remote code execution in administrative interface |
Pulse Secure |
Jake Valletta |
Advisory |
| CVE-2020-6917 |
Race Condition Allows Digital Signature Bypassing |
HP Support Assistant |
Jake Valletta, Rod Deichler |
Advisory |
| CVE-2020-6918 |
Digital Signature Not Checked Prior to Execution |
HP Support Assistant |
Jake Valletta, Rod Deichler |
Advisory |
| CVE-2020-6919 |
Server Allows Communication with Untrusted Clients |
HP Support Assistant |
Jake Valletta, Rod Deichler |
Advisory |
| CVE-2020-6920 |
Client Token Not Validated by Server |
HP Support Assistant |
Jake Valletta, Rod Deichler |
Advisory |
| CVE-2020-6921 |
Directory Traversal Leads to File Output Path Manipulation |
HP Support Assistant |
Jake Valletta, Rod Deichler |
Advisory |
| CVE-2020-6922 |
Weak Client Token Invalidation Practices Best |
HP Support Assistant |
Jake Valletta, Rod Deichler |
Advisory |
| CVE-2020-9306 |
Hardcoded credentials |
Telsa/Solarcity |
Jake Valletta, Sam Sabetan |
Blog pt1, pt2 |
| CVE-2020-12878 |
Execution with unnecessary privileges |
Telsa/Solarcity |
Jake Valletta, Sam Sabetan |
Released with 2020-12878 |
| CVE-2020-15467 |
Authenticated command injection in administrative interface (vns3:vpn) |
Cohesive Networks |
Jake Valletta |
Advisory |
| CVE-2020-25217 |
Authenticated command injection in administrative interface (GRP261x devices) |
Grandstream Networks |
Jake Valletta, Michael Maturi |
Advisory |
| CVE-2020-25218 |
Authentication bypass in administrative interface (GRP261x devices) |
Grandstream Networks |
Jake Valletta, Michael Maturi |
Advisory |
| CVE-2021-28372 |
Device Impersonation in Kalay Network Registration |
ThroughTek |
Jake Valletta, Erik Barzdukas, Dillon Franke |
Advisory, blog |