8.1
CVE-2020-5550
- EPSS 1.86%
- Veröffentlicht 08.04.2020 08:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:15
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management console, that may result in information alteration/disclosure via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plathome ≫ Easyblocks Ipv6 Firmware Version <= 2.0.1
Plathome ≫ Easyblocks Ipv6 Enterprise Firmware Version <= 2.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.86% | 0.765 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-384 Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
https://jvn.jp/en/jp/JVN89224521/index.html
https://www.plathome.co.jp/software/ipv6-enterprise-v2-0-2/
https://www.plathome.co.jp/software/ipv6-v2-0-2/