VulnerabilityModified
CVE-2020-15058
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
HIGH 8.8EPSS 0.32%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319, CWE-522
- Affected
- lindy-international/42633 firmware
- Source
- cve@mitre.org
References
- https://research.hisolutions.com/2020/05/critical-vulnerabilites-in-multiple-usb-network-servers/Broken Link, Third Party Advisory
- https://research.hisolutions.com/2020/05/critical-vulnerabilites-in-multiple-usb-network-servers/Broken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.