CVE-2020-7982
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
16/03/2020
Last modified:
24/05/2023
Description
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:openwrt:lede:*:*:*:*:*:*:*:* | 17.01.0 (including) | 17.01.7 (including) |
cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:* | 18.06.0 (including) | 18.06.7 (excluding) |
cpe:2.3:o:openwrt:openwrt:19.07.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page