CVE-2020-9034
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.90.70.3 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.30 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.25 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S250 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.65.0 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S300 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.80.1 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S350 | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.