CVE-2020-24051
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
21/08/2020
Last modified:
21/07/2021
Description
The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker can abuse this issue to execute privileged operations without authentication, for instance, to create a new Administrator user.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:moog:exvf5c-2_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:moog:exvf5c-2:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:moog:exvp7c2-3_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:moog:exvp7c2-3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page