CVE-2020-15809

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
24/03/2021
Last modified:
26/03/2021

Description

spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:spinetix:dsos:*:*:*:*:*:*:*:* 4.5.2-1.0.2-1eb2ffbd (including)
cpe:2.3:o:spinetix:hmp350_firmware:*:*:*:*:*:*:*:* 4.5.2-1.0.36229 (including)
cpe:2.3:h:spinetix:hmp350:-:*:*:*:*:*:*:*
cpe:2.3:o:spinetix:hmp300_firmware:*:*:*:*:*:*:*:* 4.5.2-1.0.36229 (including)
cpe:2.3:h:spinetix:hmp300:-:*:*:*:*:*:*:*
cpe:2.3:o:spinetix:diva_firmware:*:*:*:*:*:*:*:* 4.5.2-1.0.36229 (including)
cpe:2.3:h:spinetix:diva:-:*:*:*:*:*:*:*
cpe:2.3:o:spinetix:hmp400_firmware:*:*:*:*:*:*:*:* 4.5.2-1.0.2-1eb2ffbd (including)
cpe:2.3:h:spinetix:hmp400:-:*:*:*:*:*:*:*
cpe:2.3:o:spinetix:hmp400w_firmware:*:*:*:*:*:*:*:* 4.5.2-1.0.2-1eb2ffbd (including)
cpe:2.3:h:spinetix:hmp400w:-:*:*:*:*:*:*:*