CVE-2020-29194
Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&mode=1 in a POST request to the cgi-bin/set_factory URI.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&mode=1 in a POST request to the cgi-bin/set_factory URI.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- panasonic/wv-s2231l firmware
- Source
- cve@mitre.org
References
- https://github.com/cecada/Panasonic-WV-S2231L/blob/main/README.mdExploit, Third Party Advisory
- https://security.panasonic.com/products_technology/products/wv-s2231l/Product, Vendor Advisory
- https://github.com/cecada/Panasonic-WV-S2231L/blob/main/README.mdExploit, Third Party Advisory
- https://security.panasonic.com/products_technology/products/wv-s2231l/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.