← Back

CVE-2020-9028

nvd nist
Published: Feb 17, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).

Affected (5)

5 products
Syncserver S100 Firmware
Syncserver S200 Firmware
Syncserver S250 Firmware
Syncserver S300 Firmware
Syncserver S350 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.90.70.3
Running on/withPlatform Versions
Microchip
Syncserver S100
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.30
Running on/withPlatform Versions
Microchip
Syncserver S200
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.25
Running on/withPlatform Versions
Microchip
Syncserver S250
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.65.0
Running on/withPlatform Versions
Microchip
Syncserver S300
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.80.1
Running on/withPlatform Versions
Microchip
Syncserver S350
All versions

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.