8.8
CVE-2020-8350
- EPSS 0.12%
- Veröffentlicht 14.10.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:45
- Quelle psirt@lenovo.com
- CVE-Watchlists
- Unerledigt
An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Thinkpad Stack Wireless Router Firmware Version <= 1.1.3.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.28 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
| psirt@lenovo.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.