Lucene search

K
cveMitreCVE-2020-27691
HistoryNov 04, 2020 - 9:15 p.m.

CVE-2020-27691

2020-11-0421:15:12
CWE-79
mitre
web.nvd.nist.gov
36
cve-2020-27691
relish (verve connect)
vh510
firmware
xss
urlblocking settings
snmp settings
system log settings
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

32.7%

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.

Affected configurations

Nvd
Node
imomobileverve_connect_vh510_firmwareRange<1.0.1.6l0516
AND
imomobileverve_connect_vh510Matchl0am095a
VendorProductVersionCPE
imomobileverve_connect_vh510_firmware*cpe:2.3:o:imomobile:verve_connect_vh510_firmware:*:*:*:*:*:*:*:*
imomobileverve_connect_vh510l0am095acpe:2.3:h:imomobile:verve_connect_vh510:l0am095a:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

32.7%

Related for CVE-2020-27691