René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

116 lines
3.7 KiB
JSON

{
"id": "CVE-2020-22158",
"sourceIdentifier": "cve@mitre.org",
"published": "2020-09-14T16:15:11.590",
"lastModified": "2020-11-12T13:47:51.487",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the \"path\" or \"Services+ID\" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the \"name\" parameter with the malicious code."
},
{
"lang": "es",
"value": "Los dispositivos MediaKind (anteriormente Ericsson) versi\u00f3n 5.13.3, son vulnerables a m\u00faltiples ataques de tipo XSS reflejados y almacenados. Un atacante tiene que inyectar c\u00f3digo JavaScript directamente en los par\u00e1metros \"path\" o \"Services+ID\" y enviar la URL hacia un usuario para explotar la vulnerabilidad de tipo XSS reflejado. En el caso de una vulnerabilidad de tipo XSS almacenado, un atacante debe modificar el par\u00e1metro \"name\" con el c\u00f3digo malicioso"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:mediakind:rx8200_firmware:5.13.3:*:*:*:*:*:*:*",
"matchCriteriaId": "7A1EEB9E-45E3-495B-A09C-71A7A96B015D"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:mediakind:rx8200:-:*:*:*:*:*:*:*",
"matchCriteriaId": "369370E0-04CD-4EDE-9C0C-F2FCAD7C40E3"
}
]
}
]
}
],
"references": [
{
"url": "https://sku11army.blogspot.com/2020/02/ericsson-multiple-stored-reflected-xss.html",
"source": "cve@mitre.org",
"tags": [
"Permissions Required"
]
}
]
}