Lucene search

K
cveMitreCVE-2020-16168
HistoryAug 07, 2020 - 1:15 p.m.

CVE-2020-16168

2020-08-0713:15:10
CWE-346
mitre
web.nvd.nist.gov
26
cve-2020-16168
temi
robox os
android app
remote access
rest api
mqtt broker

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

56.3%

Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and MQTT broker used by the temi and send it custom data/requests via unspecified vectors.

Affected configurations

Nvd
Node
robotemitemi_firmwareRange<1.3.7931
AND
robotemitemiMatch-
VendorProductVersionCPE
robotemitemi_firmware*cpe:2.3:o:robotemi:temi_firmware:*:*:*:*:*:*:*:*
robotemitemi-cpe:2.3:h:robotemi:temi:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

56.3%

Related for CVE-2020-16168