4.8

CVE-2020-13527

An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LantronixXport Edge Firmware Version3.0.0.0 Updater11
   LantronixXport Edge Version-
LantronixXport Edge Firmware Version3.1.0.0 Updater9
   LantronixXport Edge Version-
LantronixXport Edge Firmware Version3.4.0.0 Updater12
   LantronixXport Edge Version-
LantronixXport Edge Firmware Version4.2.0.0 Updater7
   LantronixXport Edge Version-
LantronixSgx Firmware Version8.7.0.0 Updater1
   LantronixSgx Version-
LantronixSgx Firmware Version8.9.0.0 Updater4
   LantronixSgx Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.265
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.5 0.9 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
talos-cna@cisco.com 4.8 0.5 4.2
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.