CVE-2020-29127

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/11/2020
Last modified:
03/12/2020

Description

An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fujitsu:eternus_storage_dx200_s4_firmware:*:*:*:*:*:*:*:* 2020-11-25 (including)
cpe:2.3:h:fujitsu:eternus_storage_dx200_s4:-:*:*:*:*:*:*:*