ID

VAR-202008-0618


CVE

CVE-2020-15065


TITLE

DIGITUS DA-70254 4-Port Gigabit Network Hub Input verification vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-009040

DESCRIPTION

DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values. The vulnerability stems from the network system or product not correctly verifying the input data. No detailed vulnerability details are currently provided

Trust: 2.16

sources: NVD: CVE-2020-15065 // JVNDB: JVNDB-2020-009040 // CNVD: CNVD-2020-46818

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

category:['network device']sub_category:hub

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2020-46818

AFFECTED PRODUCTS

vendor:digitusmodel:da-70254scope:eqversion:2.073.000.e0008

Trust: 1.8

vendor:assmannmodel:electronic digitus da-70254 4-port gigabit network hub 2.073.000.e0008scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-46818 // JVNDB: JVNDB-2020-009040 // NVD: CVE-2020-15065

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-15065
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-009040
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-46818
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202008-306
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-15065
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-009040
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-46818
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-15065
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009040
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-46818 // JVNDB: JVNDB-2020-009040 // CNNVD: CNNVD-202008-306 // NVD: CVE-2020-15065

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.0

problemtype:CWE-20

Trust: 0.8

sources: JVNDB: JVNDB-2020-009040 // NVD: CVE-2020-15065

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202008-306

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-202008-306

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009040

PATCH

title:Archivartikel | DIGITUS USB 2.0 4-Port Gigabit Netzwerk Huburl:https://www.digitus.info/de/produkte/archiv/da-70254/

Trust: 0.8

sources: JVNDB: JVNDB-2020-009040

EXTERNAL IDS

db:NVDid:CVE-2020-15065

Trust: 3.1

db:JVNDBid:JVNDB-2020-009040

Trust: 0.8

db:CNVDid:CNVD-2020-46818

Trust: 0.6

db:CNNVDid:CNNVD-202008-306

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2020-46818 // JVNDB: JVNDB-2020-009040 // CNNVD: CNNVD-202008-306 // NVD: CVE-2020-15065

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-15065

Trust: 2.0

url:https://research.hisolutions.com/2020/05/critical-vulnerabilites-in-multiple-usb-network-servers/

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-15065

Trust: 0.8

url:https://research.hisolutions.com/2020/07/high-impact-vulnerabilites-in-multiple-usb-network-servers/

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2020-46818 // JVNDB: JVNDB-2020-009040 // CNNVD: CNNVD-202008-306 // NVD: CVE-2020-15065

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2020-46818
db:JVNDBid:JVNDB-2020-009040
db:CNNVDid:CNNVD-202008-306
db:NVDid:CVE-2020-15065

LAST UPDATE DATE

2025-01-30T22:42:38.912000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-46818date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009040date:2020-10-15T00:00:00
db:CNNVDid:CNNVD-202008-306date:2020-08-10T00:00:00
db:NVDid:CVE-2020-15065date:2024-11-21T05:04:44.480

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-46818date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009040date:2020-10-15T00:00:00
db:CNNVDid:CNNVD-202008-306date:2020-08-07T00:00:00
db:NVDid:CVE-2020-15065date:2020-08-07T22:15:13.430