CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microchip

syncserver_s350_firmware

7 known vulnerabilities · sorted by CVSS score

CVE-2020-9034
HIGH7.5

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.

microchip / syncserver_s100_firmware+4
Network
Published Feb 17, 2020
CVE-2020-9029
MEDIUM6.5

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.

microchip / syncserver_s100_firmware+4
Network
Published Feb 17, 2020
CVE-2020-9031
MEDIUM6.5

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.

microchip / syncserver_s100_firmware+4
Network
Published Feb 17, 2020
CVE-2020-9033
MEDIUM6.5

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.

microchip / syncserver_s100_firmware+4
Network
Published Feb 17, 2020
CVE-2020-9030
MEDIUM6.5

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.

microchip / syncserver_s100_firmware+4
Network
Published Feb 17, 2020
CVE-2020-9032
MEDIUM6.5

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.

microchip / syncserver_s100_firmware+4
Network
Published Feb 17, 2020
CVE-2020-9028
MEDIUM6.1

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).

microchip / syncserver_s100_firmware+4
Network
Published Feb 17, 2020