Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-5686


Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL.


Published

2021-01-13T10:15:15.097

Last Modified

2024-11-21T05:34:28.793

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System nec univerge_sv9500_firmware ≤ v7 Yes
Hardware nec univerge_sv9500 - No
Operating System nec univerge_sv8500_firmware ≤ s8 Yes
Hardware nec univerge_sv8500 - No

References