VulnerabilityModified
CVE-2020-11918
An attacker capable of accessing the web interface can create the backup file.
MEDIUM 5.4EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- svakom/svakom siime eye firmware
- Source
- cve@mitre.org
References
- https://seclists.org/fulldisclosure/2024/Jul/14Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/14
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.