VulnerabilityModified
CVE-2020-15809
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal.
MEDIUM 6.5EPSS 0.94%
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-918
- Affected
- spinetix/dsos · spinetix/hmp350 firmware · spinetix/hmp300 firmware · spinetix/diva firmware · spinetix/hmp400 firmware · spinetix/hmp400w firmware
- Source
- cve@mitre.org
References
- https://support.spinetix.com/wiki/DSOS_release_notesRelease Notes, Vendor Advisory
- https://support.spinetix.com/wiki/SpinetiX-SA-20:01Release Notes, Vendor Advisory
- https://support.spinetix.com/wiki/DSOS_release_notesRelease Notes, Vendor Advisory
- https://support.spinetix.com/wiki/SpinetiX-SA-20:01Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.