10

CVE-2020-12030

Emerson WirelessHART Gateway

There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emerson ≫ Wireless 1410 Gateway Firmware Version >= 4.6.43 <= 4.7.84
   Emerson ≫ Wireless 1410 Gateway Version -
Emerson ≫ Wireless 1420 Gateway Firmware Version >= 4.6.43 <= 4.7.84
   Emerson ≫ Wireless 1420 Gateway Version -
Emerson ≫ Wireless 1552wu Gateway Firmware Version >= 4.6.43 <= 4.7.84
   Emerson ≫ Wireless 1552wu Gateway Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.13% 0.635
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
DHS.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://us-cert.cisa.gov/ics/advisories/icsa-20-135-02
Third Party Advisory
US Government Resource