Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Azure Sphere
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-16970 1 Microsoft 1 Azure Sphere 2023-12-31 7.2 HIGH 8.1 HIGH
Azure Sphere Unsigned Code Execution Vulnerability
CVE-2020-16984 1 Microsoft 1 Azure Sphere 2023-12-31 7.2 HIGH 7.3 HIGH
Azure Sphere Unsigned Code Execution Vulnerability
CVE-2020-16992 1 Microsoft 1 Azure Sphere 2023-12-31 7.2 HIGH 7.5 HIGH
Azure Sphere Elevation of Privilege Vulnerability
CVE-2020-16991 1 Microsoft 1 Azure Sphere 2023-12-31 2.1 LOW 7.3 HIGH
Azure Sphere Unsigned Code Execution Vulnerability
CVE-2020-16987 1 Microsoft 1 Azure Sphere 2023-12-31 7.2 HIGH 7.3 HIGH
Azure Sphere Unsigned Code Execution Vulnerability
CVE-2020-16994 1 Microsoft 1 Azure Sphere 2023-12-31 2.1 LOW 7.3 HIGH
Azure Sphere Unsigned Code Execution Vulnerability
CVE-2021-28460 1 Microsoft 1 Azure Sphere 2023-12-29 4.6 MEDIUM 8.1 HIGH
Azure Sphere Unsigned Code Execution Vulnerability
CVE-2021-26429 1 Microsoft 1 Azure Sphere 2023-12-28 4.6 MEDIUM 7.7 HIGH
Azure Sphere Elevation of Privilege Vulnerability
CVE-2020-35608 1 Microsoft 1 Azure Sphere 2020-12-23 7.2 HIGH 7.8 HIGH
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.