CVE-2018-6020

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
09/05/2018
Last modified:
13/06/2018

Description

In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:silextechnology:sd-320an_firmware:*:*:*:*:*:*:*:* 2.01 (including)
cpe:2.3:h:silextechnology:sd-320an:-:*:*:*:*:*:*:*
cpe:2.3:o:silextechnology:geh-sd-320an_firmware:*:*:*:*:*:*:*:* geh-1.1 (including)
cpe:2.3:h:silextechnology:geh-sd-320an:-:*:*:*:*:*:*:*
cpe:2.3:o:silextechnology:geh-500_firmware:*:*:*:*:*:*:*:* 1.54 (including)
cpe:2.3:h:silextechnology:geh-500:-:*:*:*:*:*:*:*
cpe:2.3:o:silextechnology:sx-500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:silextechnology:sx-500:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools