10
CVE-2020-12493
- EPSS 1.4%
- Veröffentlicht 29.05.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:47
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
Critical Vulnerability in SWARCO CPU LS4000
An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb operations with connected devices.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Swarco ≫ Cpu Ls4000 Firmware Versiong4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.4% | 0.69 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| info@cert.vde.com | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://cert.vde.com/de-de/advisories/vde-2020-016