CVE-2020-15809
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
24/03/2021
Last modified:
26/03/2021
Description
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:spinetix:dsos:*:*:*:*:*:*:*:* | 4.5.2-1.0.2-1eb2ffbd (including) | |
| cpe:2.3:o:spinetix:hmp350_firmware:*:*:*:*:*:*:*:* | 4.5.2-1.0.36229 (including) | |
| cpe:2.3:h:spinetix:hmp350:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:spinetix:hmp300_firmware:*:*:*:*:*:*:*:* | 4.5.2-1.0.36229 (including) | |
| cpe:2.3:h:spinetix:hmp300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:spinetix:diva_firmware:*:*:*:*:*:*:*:* | 4.5.2-1.0.36229 (including) | |
| cpe:2.3:h:spinetix:diva:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:spinetix:hmp400_firmware:*:*:*:*:*:*:*:* | 4.5.2-1.0.2-1eb2ffbd (including) | |
| cpe:2.3:h:spinetix:hmp400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:spinetix:hmp400w_firmware:*:*:*:*:*:*:*:* | 4.5.2-1.0.2-1eb2ffbd (including) | |
| cpe:2.3:h:spinetix:hmp400w:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



