mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
144 lines
5.8 KiB
JSON
144 lines
5.8 KiB
JSON
{
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"data_version": "4.0",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2020-36531",
|
|
"TITLE": "SevOne Network Management System Device Manager Page injection",
|
|
"REQUESTER": "cna@vuldb.com",
|
|
"ASSIGNER": "cna@vuldb.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"generator": "vuldb.com",
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "SevOne",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "Network Management System",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "5.7.2.0"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.1"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.2"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.3"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.4"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.5"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.6"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.7"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.8"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.9"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.10"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.11"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.12"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.13"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.14"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.15"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.16"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.17"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.18"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.19"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.20"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.21"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.22"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-74 Injection"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely."
|
|
}
|
|
]
|
|
},
|
|
"credit": "Calvin Phang",
|
|
"impact": {
|
|
"cvss": {
|
|
"version": "3.1",
|
|
"baseScore": "6.3",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2020/Oct/5",
|
|
"refsource": "MISC",
|
|
"name": "http://seclists.org/fulldisclosure/2020/Oct/5"
|
|
},
|
|
{
|
|
"url": "https://vuldb.com/?id.162263",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?id.162263"
|
|
}
|
|
]
|
|
}
|
|
} |