ID

VAR-202009-1673


TITLE

Shenzhen Wangxin Technology Co., Ltd. Wangxin Cloud device has unauthorized access vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-48674

DESCRIPTION

Shenzhen Wangxin Technology Co., Ltd. is committed to the field of global shared computing and blockchain, and amplifies the power of everyone through technological innovation. Shenzhen Netheart Technology Co., Ltd. Netheart Cloud equipment has an unauthorized access vulnerability. Attackers can use this vulnerability to gain unauthorized access to the system to obtain the device SN code/set the device access method/basic information/LAN port information/extract logs/run the device Restart/reset the device, etc.

Trust: 0.6

sources: CNVD: CNVD-2020-48674

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-48674

AFFECTED PRODUCTS

vendor:wangxinmodel:cloud equipmentscope:eqversion:v3.1.5

Trust: 0.6

sources: CNVD: CNVD-2020-48674

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-48674
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2020-48674
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-48674

PATCH

title:Shenzhen Wangxin Technology Co., Ltd. Wangxin Cloud device has unauthorized access vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/227475

Trust: 0.6

sources: CNVD: CNVD-2020-48674

EXTERNAL IDS

db:CNVDid:CNVD-2020-48674

Trust: 0.6

sources: CNVD: CNVD-2020-48674

SOURCES

db:CNVDid:CNVD-2020-48674

LAST UPDATE DATE

2022-05-04T09:32:43.534000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-48674date:2020-08-27T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-48674date:2020-09-10T00:00:00