CVE-2020-5686 Vulnerability Details

  /     /     /  

CVE-2020-5686 Metadata Quick Info

CVE Published: 13/01/2021 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: jpcert | Vendor: NEC Corporation | Product: UNIVERGE SV9500/SV8500 series
Status : PUBLISHED

CVE-2020-5686 Description

Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Incorrect Implementation of Authentication Algorithm
Source: NEC Corporation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).