
CVE-2019-19561
https://notcve.org/view.php?id=CVE-2019-19561
15 Nov 2020 — A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information. Una configuración inapropiada en la interfaz de depuración en Mercedes-Benz HERMES versión 1.5, permite a un atacante con acceso físico directo al hardware del dispositivo obtener información del módem celular • https://media.daimler.com/marsMediaSite/en/instance/ko/Mercedes-Benz-and-360-Group-to-join-forces-Mercedes-Benz-and-360-Group-with-its-Cyber-Security-Brain-work-together-to-strengthen-car-IT-security-for-industry.xhtml?oid=45208829 • CWE-922: Insecure Storage of Sensitive Information •

CVE-2019-19557
https://notcve.org/view.php?id=CVE-2019-19557
15 Nov 2020 — A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. Una configuración inapropiada en la interfaz de depuración en Mercedes-Benz HERMES versión 1, permite a un atacante con acceso físico directo al hardware del dispositivo obtener información del módem celular • https://media.daimler.com/marsMediaSite/en/instance/ko/Mercedes-Benz-and-360-Group-to-join-forces-Mercedes-Benz-and-360-Group-with-its-Cyber-Security-Brain-work-together-to-strengthen-car-IT-security-for-industry.xhtml?oid=45208829 • CWE-922: Insecure Storage of Sensitive Information •

CVE-2019-19563
https://notcve.org/view.php?id=CVE-2019-19563
15 Nov 2020 — A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. Una configuración inapropiada en la interfaz de depuración en Mercedes-Benz HERMES versión 2.1, permite a un atacante con acceso físico directo al hardware del dispositivo obtener información del módem celular • https://media.daimler.com/marsMediaSite/en/instance/ko/Mercedes-Benz-and-360-Group-to-join-forces-Mercedes-Benz-and-360-Group-with-its-Cyber-Security-Brain-work-together-to-strengthen-car-IT-security-for-industry.xhtml?oid=45208829 •

CVE-2019-19560
https://notcve.org/view.php?id=CVE-2019-19560
15 Nov 2020 — An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information. Una configuración inapropiada en la interfaz de depuración en Mercedes-Benz HERMES versión 1.5, permite a un atacante con acceso físico directo al hardware del dispositivo obtener información del módem celular • https://media.daimler.com/marsMediaSite/en/instance/ko/Mercedes-Benz-and-360-Group-to-join-forces-Mercedes-Benz-and-360-Group-with-its-Cyber-Security-Brain-work-together-to-strengthen-car-IT-security-for-industry.xhtml?oid=45208829 • CWE-287: Improper Authentication •

CVE-2019-19556
https://notcve.org/view.php?id=CVE-2019-19556
15 Nov 2020 — An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information. Una omisión de autenticación en la interfaz de depuración en Mercedes-Benz HERMES versión 1, permite a un atacante con acceso físico al hardware del dispositivo obtener información del sistema • https://media.daimler.com/marsMediaSite/en/instance/ko/Mercedes-Benz-and-360-Group-to-join-forces-Mercedes-Benz-and-360-Group-with-its-Cyber-Security-Brain-work-together-to-strengthen-car-IT-security-for-industry.xhtml?oid=45208829 •

CVE-2019-19562
https://notcve.org/view.php?id=CVE-2019-19562
15 Nov 2020 — An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information. Una omisión de autenticación en la interfaz de depuración en Mercedes-Benz HERMES versión 2.1, permite a un atacante con acceso físico al hardware del dispositivo obtener información del sistema • https://media.daimler.com/marsMediaSite/en/instance/ko/Mercedes-Benz-and-360-Group-to-join-forces-Mercedes-Benz-and-360-Group-with-its-Cyber-Security-Brain-work-together-to-strengthen-car-IT-security-for-industry.xhtml?oid=45208829 • CWE-287: Improper Authentication •

CVE-2019-11224
https://notcve.org/view.php?id=CVE-2019-11224
15 May 2019 — HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection. Los dispositvos HARMAN AMX MVP5150 versión v2.87.13, permiten la inyección de comandos remota en el sistema operativo. • https://github.com/Insecurities/CVE-2019-11224 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2015-8362
https://notcve.org/view.php?id=CVE-2015-8362
22 Jan 2016 — The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984. La función setUpSubtleUserAccount en /bin/bw en dispositivos Harman AMX en versiones anteriores a 2015-10-12 tiene una contraseña embebida para la cuenta BlackWidow, lo que facilita a atacantes remotos obtener acceso a través de un... • http://blog.sec-consult.com/2016/01/deliberately-hidden-backdoor-account-in.html • CWE-255: Credentials Management Errors •

CVE-2016-1984
https://notcve.org/view.php?id=CVE-2016-1984
22 Jan 2016 — The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362. La función setUpSubtleUserAccount en /bin/bw en dispositivos Harman AMX en versiones anteriores a 2016-01-20 tiene una contraseña embebida para la cuenta 1MB@tMaN, lo que facilita a atacantes remotos obtener acceso a través de una se... • http://blog.sec-consult.com/2016/01/deliberately-hidden-backdoor-account-in.html • CWE-255: Credentials Management Errors •