ID

VAR-202407-2555


CVE

CVE-2020-11918


TITLE

Svakom  of  Siime Eye  Vulnerability related to plaintext storage of important information in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2020-018372

DESCRIPTION

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file. Svakom of Siime Eye The firmware contains a vulnerability related to plaintext storage of sensitive information.Information may be obtained and information may be tampered with. ------------------------------------------ [Vulnerability Type] Incorrect Access Control ------------------------------------------ [Vendor of Product] Svakom ------------------------------------------ [Affected Product Code Base] Siime Eye - 14.1.00000001.3.330.0.0.3.14 ------------------------------------------ [Affected Component] Siime Eye ------------------------------------------ [Attack Type] Context-dependent ------------------------------------------ [Impact Information Disclosure] true ------------------------------------------ [Attack Vectors] A backup file must be found or created by an attacker in order to exploit this vulnerability. ------------------------------------------ [Reference] N/A ------------------------------------------ [Has vendor confirmed or acknowledged the vulnerability?] true ------------------------------------------ [Discoverer] Willem Westerhof, Jasper Nota, Edwin Gozeling from Qbit in assignment of the Consumentenbond Use CVE-2020-11918

Trust: 1.71

sources: NVD: CVE-2020-11918 // JVNDB: JVNDB-2020-018372 // PACKETSTORM: 179797

AFFECTED PRODUCTS

vendor:svakommodel:siime eyescope:eqversion:14.1.00000001.3.330.0.0.3.14

Trust: 1.0

vendor:svakommodel:siime eyescope: - version: -

Trust: 0.8

vendor:svakommodel:siime eyescope:eqversion:siime eye firmware 14.1.00000001.3.330.0.0.3.14

Trust: 0.8

vendor:svakommodel:siime eyescope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-018372 // NVD: CVE-2020-11918

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2020-11918
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2020-018372
value: MEDIUM

Trust: 0.8

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2020-11918
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.5
version: 3.1

Trust: 1.0

OTHER: JVNDB-2020-018372
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-018372 // NVD: CVE-2020-11918

PROBLEMTYPE DATA

problemtype:CWE-312

Trust: 1.0

problemtype:Plaintext storage of important information (CWE-312) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-018372 // NVD: CVE-2020-11918

TYPE

info disclosure

Trust: 0.1

sources: PACKETSTORM: 179797

EXTERNAL IDS

db:NVDid:CVE-2020-11918

Trust: 2.8

db:JVNDBid:JVNDB-2020-018372

Trust: 0.8

db:OTHERid:NONE

Trust: 0.1

db:PACKETSTORMid:179797

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2020-018372 // PACKETSTORM: 179797 // NVD: CVE-2020-11918

REFERENCES

url:https://seclists.org/fulldisclosure/2024/jul/14

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-11918

Trust: 0.9

sources: JVNDB: JVNDB-2020-018372 // PACKETSTORM: 179797 // NVD: CVE-2020-11918

CREDITS

Willem Westerhof | Secura

Trust: 0.1

sources: OTHER: None

SOURCES

db:OTHERid: -
db:JVNDBid:JVNDB-2020-018372
db:PACKETSTORMid:179797
db:NVDid:CVE-2020-11918

LAST UPDATE DATE

2025-04-26T20:51:18.337000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-018372date:2025-04-25T03:09:00
db:NVDid:CVE-2020-11918date:2025-04-24T13:42:14.090

SOURCES RELEASE DATE

db:OTHERid: - date:2024-07-26T13:11:06
db:JVNDBid:JVNDB-2020-018372date:2025-04-25T00:00:00
db:PACKETSTORMid:179797date:2024-07-30T12:35:43
db:NVDid:CVE-2020-11918date:2024-11-07T18:15:15.450