ID

VAR-202003-1392


CVE

CVE-2020-9476


TITLE

ARRIS TG1692A Inadequate protection of credentials on devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-002415

DESCRIPTION

ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding. ARRIS TG1692A Devices contain vulnerabilities in insufficient protection of credentials.Information may be obtained. ARRIS TG1692A is a modem of ARRIS company in the United States. A security vulnerability exists in ARRIS TG1692A

Trust: 2.16

sources: NVD: CVE-2020-9476 // JVNDB: JVNDB-2020-002415 // CNVD: CNVD-2020-15960

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-15960

AFFECTED PRODUCTS

vendor:commscopemodel:arris tg1692ascope:eqversion:9.1.103de2

Trust: 1.6

vendor:arris groupmodel:tg1692ascope:eqversion:brgcaa 1.1.53

Trust: 0.8

vendor:arrismodel:tg1692ascope: - version: -

Trust: 0.6

vendor:commscopemodel:arris tg1692ascope:eqversion: -

Trust: 0.6

sources: CNVD: CNVD-2020-15960 // JVNDB: JVNDB-2020-002415 // CNNVD: CNNVD-202003-188 // NVD: CVE-2020-9476

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-9476
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-002415
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-15960
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202003-188
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-9476
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-002415
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-15960
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-9476
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-002415
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-15960 // JVNDB: JVNDB-2020-002415 // CNNVD: CNNVD-202003-188 // NVD: CVE-2020-9476

PROBLEMTYPE DATA

problemtype:CWE-326

Trust: 1.0

problemtype:CWE-522

Trust: 0.8

sources: JVNDB: JVNDB-2020-002415 // NVD: CVE-2020-9476

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202003-188

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202003-188

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-002415

PATCH

title:WELCOME TO ARRIS CONSUMER SUPPORTurl:https://arris.secure.force.com/consumers/ConsumerProductSupport

Trust: 0.8

title:Patch for ARRIS TG1692A Information Disclosure Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/207649

Trust: 0.6

title:ARRIS TG1692A Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=111262

Trust: 0.6

sources: CNVD: CNVD-2020-15960 // JVNDB: JVNDB-2020-002415 // CNNVD: CNNVD-202003-188

EXTERNAL IDS

db:NVDid:CVE-2020-9476

Trust: 3.0

db:JVNDBid:JVNDB-2020-002415

Trust: 0.8

db:CNVDid:CNVD-2020-15960

Trust: 0.6

db:CNNVDid:CNNVD-202003-188

Trust: 0.6

sources: CNVD: CNVD-2020-15960 // JVNDB: JVNDB-2020-002415 // CNNVD: CNNVD-202003-188 // NVD: CVE-2020-9476

REFERENCES

url:https://arris.secure.force.com/consumers/consumerproductsupport

Trust: 2.2

url:https://nvd.nist.gov/vuln/detail/cve-2020-9476

Trust: 2.0

url:https://medium.com/@rsantos_14778/info-disclosure-cve-2020-9476-494a08298c6b

Trust: 1.4

url:https://medium.com/%40rsantos_14778/info-disclosure-cve-2020-9476-494a08298c6b

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-9476

Trust: 0.8

url:https://medium.com/@rsantos_14778/info

Trust: 0.6

sources: CNVD: CNVD-2020-15960 // JVNDB: JVNDB-2020-002415 // CNNVD: CNNVD-202003-188 // NVD: CVE-2020-9476

SOURCES

db:CNVDid:CNVD-2020-15960
db:JVNDBid:JVNDB-2020-002415
db:CNNVDid:CNNVD-202003-188
db:NVDid:CVE-2020-9476

LAST UPDATE DATE

2024-11-23T22:33:33.445000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-15960date:2020-03-07T00:00:00
db:JVNDBid:JVNDB-2020-002415date:2020-03-16T00:00:00
db:CNNVDid:CNNVD-202003-188date:2020-03-13T00:00:00
db:NVDid:CVE-2020-9476date:2024-11-21T05:40:43.413

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-15960date:2020-03-07T00:00:00
db:JVNDBid:JVNDB-2020-002415date:2020-03-16T00:00:00
db:CNNVDid:CNNVD-202003-188date:2020-03-04T00:00:00
db:NVDid:CVE-2020-9476date:2020-03-04T19:15:14.010