ID

VAR-201607-0763


TITLE

Multiple holes in Cube Digital Media Neoscreen

Trust: 0.6

sources: CNVD: CNVD-2016-05645

DESCRIPTION

Cube Digital Media Neoscreen is a smart display from Cube Digital Media of France. Cube Digital Media Neoscreen 4.5 has a security vulnerability. An attacker could use this vulnerability to execute arbitrary script code in the context of an affected site, steal cookie-based authentication, control applications, access or modify data, and bypass authentication mechanisms. Neoscreen 4.5 is vulnerable; other versions may also be affected

Trust: 1.35

sources: CNVD: CNVD-2016-05645 // CNNVD: CNNVD-201607-988 // BID: 92106

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-05645

AFFECTED PRODUCTS

vendor:cubemodel:digital media neoscreenscope:eqversion:4.5

Trust: 0.9

vendor:cubemodel:digital media neoscreenscope:neversion:5.0

Trust: 0.3

sources: CNVD: CNVD-2016-05645 // BID: 92106

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-05645
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-05645
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-05645

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201607-988

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201607-988

PATCH

title:CubeDigitalMediaNeoscreen has multiple vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/79863

Trust: 0.6

sources: CNVD: CNVD-2016-05645

EXTERNAL IDS

db:BIDid:92106

Trust: 1.5

db:CNVDid:CNVD-2016-05645

Trust: 0.6

db:CNNVDid:CNNVD-201607-988

Trust: 0.6

sources: CNVD: CNVD-2016-05645 // BID: 92106 // CNNVD: CNNVD-201607-988

REFERENCES

url:http://www.securityfocus.com/bid/92106

Trust: 1.2

url:http://seclists.org/bugtraq/2016/jul/113

Trust: 0.3

url:http://seclists.org/bugtraq/2016/jul/114

Trust: 0.3

url:http://seclists.org/bugtraq/2016/jul/115

Trust: 0.3

url:http://www.cube-display.fr/

Trust: 0.3

sources: CNVD: CNVD-2016-05645 // BID: 92106 // CNNVD: CNNVD-201607-988

CREDITS

Discovered by Alex Haynes

Trust: 0.9

sources: BID: 92106 // CNNVD: CNNVD-201607-988

SOURCES

db:CNVDid:CNVD-2016-05645
db:BIDid:92106
db:CNNVDid:CNNVD-201607-988

LAST UPDATE DATE

2022-05-17T01:50:58.745000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-05645date:2016-07-29T00:00:00
db:BIDid:92106date:2016-07-24T00:00:00
db:CNNVDid:CNNVD-201607-988date:2016-07-27T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-05645date:2016-07-29T00:00:00
db:BIDid:92106date:2016-07-24T00:00:00
db:CNNVDid:CNNVD-201607-988date:2016-07-27T00:00:00