VulnerabilityDeferred
CVE-2020-36921
RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files.
MEDIUM 6.9EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-548
- Source
- disclosure@vulncheck.com
References
- https://cxsecurity.com/issue/WLB-2020110130
- https://exchange.xforce.ibmcloud.com/vulnerabilities/191803
- https://packetstormsecurity.com/files/160073
- https://www.red-v.tv/
- https://www.vulncheck.com/advisories/red-v-super-digital-signage-system-log-information-disclosure-vulnerability
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5609.php
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.