121 lines
3.8 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2020-9477",
"sourceIdentifier": "cve@mitre.org",
"published": "2020-03-04T19:15:14.073",
"lastModified": "2023-11-07T03:26:54.540",
"vulnStatus": "Modified",
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capture packets at the time of authentication and gain access to the cleartext password. An attacker could use this access to create a new user account or control the device."
},
{
"lang": "es",
"value": "Se detect\u00f3 un problema en los dispositivos HUMAX HGA12R-02 BRGCAA versi\u00f3n 1.1.53. Una vulnerabilidad en la funcionalidad de autenticaci\u00f3n en la interfaz basada en web podr\u00eda permitir a un atacante remoto no autenticado capturar paquetes al momento de la autenticaci\u00f3n y conseguir acceso a la contrase\u00f1a en texto sin cifrar. Un atacante podr\u00eda usar este acceso para crear una nueva cuenta de usuario o controlar el dispositivo."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:humaxdigital:hga12r-02_firmware:brgcaa1.1.53:*:*:*:*:*:*:*",
"matchCriteriaId": "80199A20-F1AD-4A0E-90EC-A418877F981F"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:humaxdigital:hga12r-02:-:*:*:*:*:*:*:*",
"matchCriteriaId": "766FA815-C4FA-41ED-A8AC-CC725FAEA798"
}
]
}
]
}
],
"references": [
{
"url": "https://medium.com/%40rsantos_14778/info-disclosure-cve-2020-9477-29d0ca48d4fa",
"source": "cve@mitre.org"
2023-04-24 12:24:31 +02:00
},
{
"url": "https://uk.humaxdigital.com/network/hga12r-02/",
"source": "cve@mitre.org",
"tags": [
"Product",
"Vendor Advisory"
]
}
]
}