CVE-2020-10922
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of proper input validation prior to further processing user requests. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-10527.
Affected (1)
Products: Automationdirect: C More Hmi Ea9 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.52 |
| Running on/with | Platform Versions |
|---|---|
Automationdirect Ea9 Pgmsw | All versions |
Automationdirect Ea9 Rhmi | All versions |
Automationdirect Ea9 T10cl | All versions |
Automationdirect Ea9 T10wcl | All versions |
Automationdirect Ea9 T12cl | All versions |
Automationdirect Ea9 T15cl | All versions |
Automationdirect Ea9 T15cl R | All versions |
Automationdirect Ea9 T6cl | All versions |
Automationdirect Ea9 T6cl R | All versions |
Automationdirect Ea9 T7cl | All versions |
Automationdirect Ea9 T7cl R | All versions |
Automationdirect Ea9 T8cl | All versions |
References (2)
Source: zdi-disclosures@trendmicro.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.