9.8
CVE-2020-28877
- EPSS 0.46%
- Veröffentlicht 20.11.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:23:13
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WDR7660, WDR7800, WDR8400, WDR8500, WDR8600, WDR8620, WDR8640, WDR8660, WR880N, WR886N, WR890N, WR890N, WR882N, and WR708N.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Wdr7400 Firmware Version-
Tp-link ≫ Wdr7500 Firmware Version-
Tp-link ≫ Wdr7660 Firmware Version-
Tp-link ≫ Wdr7800 Firmware Version-
Tp-link ≫ Wdr8400 Firmware Version-
Tp-link ≫ Wdr8500 Firmware Version-
Tp-link ≫ Wdr8600 Firmware Version-
Tp-link ≫ Wdr8620 Firmware Version-
Tp-link ≫ Wdr8640 Firmware Version-
Tp-link ≫ Wdr8660 Firmware Version-
Tp-link ≫ Wr880n Firmware Version-
Tp-link ≫ Wr886n Firmware Version-
Tp-link ≫ Wr890n Firmware Version-
Tp-link ≫ Wr890n Firmware Version-
Tp-link ≫ Wr882n Firmware Version-
Tp-link ≫ Wr708n Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.46% | 0.612 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.