CVE-2019-12804

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
10/07/2019
Last modified:
28/02/2023

Description

In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hunesion:i-onenet:*:*:*:*:*:*:*:* 3.0.7 (including) 3.0.53 (including)
cpe:2.3:a:hunesion:i-onenet:*:*:*:*:*:*:*:* 4.0.4 (including) 4.0.16 (including)