VulnerabilityModified
CVE-2020-5637
Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver.
MEDIUM 6.8EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a malicious program.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-354
- Affected
- necplatforms/aterm sa3500g firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN55917325/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN55917325/index.htmlThird Party Advisory
- https://www.necplatforms.co.jp/product/security_ap/info_20201211.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN55917325/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN55917325/index.htmlThird Party Advisory
- https://www.necplatforms.co.jp/product/security_ap/info_20201211.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.