Lucene search

K
nvd[email protected]NVD:CVE-2020-27690
HistoryNov 04, 2020 - 9:15 p.m.

CVE-2020-27690

2020-11-0421:15:12
CWE-120
web.nvd.nist.gov
4
relish vh510 device
firmware 1.0.1.6l0516
buffer overflow
web management portal
boa server crash

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.8

Confidence

High

EPSS

0

Percentile

5.1%

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal. When a POST request is sent to /boaform/admin/formDOMAINBLK with a large blkDomain value, the Boa server crashes.

Affected configurations

Nvd
Node
imomobileverve_connect_vh510_firmwareRange<1.0.1.6l0516
AND
imomobileverve_connect_vh510Matchl0am095a
VendorProductVersionCPE
imomobileverve_connect_vh510_firmware*cpe:2.3:o:imomobile:verve_connect_vh510_firmware:*:*:*:*:*:*:*:*
imomobileverve_connect_vh510l0am095acpe:2.3:h:imomobile:verve_connect_vh510:l0am095a:*:*:*:*:*:*:*

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.8

Confidence

High

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2020-27690