ID

VAR-202007-1472


TITLE

UFIDA Network Technology Co., Ltd. UFIDA NC Cloud has unauthorized access vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-31824

DESCRIPTION

NC Cloud is a new generation of cloud ERP products developed by UFIDA's IoT, big data, artificial intelligence and other technologies. Yonyou Network Technology Co., Ltd. Yonyou NC Cloud has an unauthorized access vulnerability, which can be exploited by attackers to cause data information leakage.

Trust: 0.6

sources: CNVD: CNVD-2020-31824

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-31824

AFFECTED PRODUCTS

vendor:ufida networkmodel:nc cloudscope:eqversion:6.5

Trust: 0.6

sources: CNVD: CNVD-2020-31824

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-31824
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2020-31824
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-31824

PATCH

title:UFIDA NC has unauthorized access vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/220497

Trust: 0.6

sources: CNVD: CNVD-2020-31824

EXTERNAL IDS

db:CNVDid:CNVD-2020-31824

Trust: 0.6

sources: CNVD: CNVD-2020-31824

SOURCES

db:CNVDid:CNVD-2020-31824

LAST UPDATE DATE

2022-05-04T09:46:19.853000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-31824date:2020-09-28T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-31824date:2020-07-13T00:00:00