CVE-2020-5686
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL.
Affected (2)
Products: Nec: Univerge Sv9500 Firmware, Univerge Sv8500 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From v1 to v7 |
| Running on/with | Platform Versions |
|---|---|
Nec Univerge Sv9500 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From s6 to s8 |
| Running on/with | Platform Versions |
|---|---|
Nec Univerge Sv8500 | All versions |
References (4)
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.