Lucene search

K
cveMitreCVE-2020-27690
HistoryNov 04, 2020 - 9:15 p.m.

CVE-2020-27690

2020-11-0421:15:12
CWE-120
mitre
web.nvd.nist.gov
36
cve-2020-27690
relish
verve connect
vh510
firmware
buffer overflow
web management
nvd

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.8

Confidence

High

EPSS

0

Percentile

5.1%

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal. When a POST request is sent to /boaform/admin/formDOMAINBLK with a large blkDomain value, the Boa server crashes.

Affected configurations

Nvd
Node
imomobileverve_connect_vh510_firmwareRange<1.0.1.6l0516
AND
imomobileverve_connect_vh510Matchl0am095a
VendorProductVersionCPE
imomobileverve_connect_vh510_firmware*cpe:2.3:o:imomobile:verve_connect_vh510_firmware:*:*:*:*:*:*:*:*
imomobileverve_connect_vh510l0am095acpe:2.3:h:imomobile:verve_connect_vh510:l0am095a:*:*:*:*:*:*:*

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.8

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2020-27690