Lucene search

K
cveIcscertCVE-2020-12046
HistoryMay 14, 2020 - 9:15 p.m.

CVE-2020-12046

2020-05-1421:15:13
CWE-347
icscert
web.nvd.nist.gov
26
cve-2020-12046
opto 22
softpac
firmware update
cybersecurity

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.7%

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files.

Affected configurations

Nvd
Node
opto22softpac_projectRange9.6
VendorProductVersionCPE
opto22softpac_project*cpe:2.3:a:opto22:softpac_project:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Opto 22 SoftPAC Project",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "SoftPAC Project Version 9.6 and prior"
      }
    ]
  }
]

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for CVE-2020-12046