9.8
CVE-2020-36902
- EPSS 0.99%
- Veröffentlicht 10.12.2025 21:16:03
- Zuletzt bearbeitet 30.12.2025 20:31:06
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
UBICOD Medivision Digital Signage 1.5.1 Authorization Bypass via User Privileges
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Medivision ≫ Medivision Digital Signage Firmware Version1.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.99% | 0.58 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
http://www.medivision.co.kr
https://www.exploit-db.com/exploits/48684
https://www.vulncheck.com/advisories/ubicod-medivision-digital-signage-authorization-bypass-via-user-privileges
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5575.php