CVE-2020-5548
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware Rev.11.01.33 and earlier, RTX830 firmware Rev.15.02.09 and earlier, RTX1200 firmware Rev.10.01.76 and earlier, RTX1210 firmware Rev.14.01.33 and earlier, RTX3500 firmware Rev.14.00.26 and earlier, and RTX5000 firmware Rev.14.00.26 and earlier), Yamaha Broadband VoIP Router(NVR500 firmware Rev.11.00.38 and earlier), and Yamaha Firewall(FWX120 firmware Rev.11.03.27 and earlier) allow remote attackers to cause a denial of service via unspecified vectors.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.02.09 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx830 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.01.14 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Nvr510 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.00.15 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Nvr700w | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 14.01.33 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx1210 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 14.00.26 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx5000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 14.00.26 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx3500 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 11.03.27 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Fwx120 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 11.01.33 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx810 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 11.00.38 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Nvr500 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.01.76 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx1200 | All versions |
References (4)
Source: vultures@jpcert.or.jp
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.