ID

VAR-202011-1575


TITLE

Unauthorized access vulnerabilities exist in the web services of Unicom Optic Cat HG6543C, HG6201U, HG2201U

Trust: 0.6

sources: CNVD: CNVD-2020-58484

DESCRIPTION

China United Network Communications Group Co., Ltd. ("China Unicom") is mainly engaged in fixed communication services, mobile communication services, domestic and international communication facilities service services, data communication services, network access services, various telecommunication value-added services, and communication information Business-related system integration business, etc. Unauthorized access vulnerabilities exist in the web services of Unicom Optic Cat HG6543C, HG6201U, and HG2201U. Attackers can use the vulnerability to perform any operations that require authentication (including operations that can only be performed by privileged accounts by constructing specific URL requests.

Trust: 0.6

sources: CNVD: CNVD-2020-58484

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-58484

AFFECTED PRODUCTS

vendor:united network groupmodel:unicom optical cat hg2201uscope: - version: -

Trust: 0.6

vendor:united network groupmodel:unicom optical cat hg6543cscope: - version: -

Trust: 0.6

vendor:united network groupmodel:unicom optical cat hg6201uscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-58484

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-58484
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2020-58484
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-58484

EXTERNAL IDS

db:CNVDid:CNVD-2020-58484

Trust: 0.6

sources: CNVD: CNVD-2020-58484

SOURCES

db:CNVDid:CNVD-2020-58484

LAST UPDATE DATE

2022-05-04T09:55:26.507000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-58484date:2020-10-25T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-58484date:2020-11-27T00:00:00