ID

VAR-202002-1702


TITLE

Logical Defect Vulnerability in Shijiazhuang Hejia Technology Co., Ltd. Computer Room Dynamic Monitoring System

Trust: 0.6

sources: CNVD: CNVD-2020-04560

DESCRIPTION

The equipment room moving ring monitoring system is a monitoring function of the equipment room's important environment and power equipment, including environmental equipment monitoring (temperature, humidity, smoke, flooding, precision air conditioning, ordinary air conditioning, new fans, etc.), power equipment monitoring (power distribution, Generator, UPS, battery, lightning arrester, etc.), security equipment monitoring (fire protection, access control, video, etc.), etc. Shijiazhuang Hejia Technology Co., Ltd.'s computer room dynamic ring monitoring system has a logical flaw. An attacker can use this vulnerability to reset the administrator and other user passwords.

Trust: 0.6

sources: CNVD: CNVD-2020-04560

IOT TAXONOMY

category:['IoT', 'ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-04560

AFFECTED PRODUCTS

vendor:shijiazhuang hejiamodel:dynamic ring monitoring systemscope:lteversion:<=2.1.8

Trust: 0.6

sources: CNVD: CNVD-2020-04560

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-04560
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-04560
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-04560

PATCH

title:Logic loophole in loop monitoring systemurl:https://www.cnvd.org.cn/patchinfo/show/196455

Trust: 0.6

sources: CNVD: CNVD-2020-04560

EXTERNAL IDS

db:CNVDid:CNVD-2020-04560

Trust: 0.6

sources: CNVD: CNVD-2020-04560

SOURCES

db:CNVDid:CNVD-2020-04560

LAST UPDATE DATE

2022-05-04T08:34:43.443000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-04560date:2020-02-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-04560date:2020-02-21T00:00:00