CVE-2020-10871
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other (more complex) ways, and there is no plan to restrict the information further
**EN DISPUTA** En OpenWrt LuCI versiones git-20.x, unos atacantes no autenticados remotos pueden recuperar la lista de paquetes y servicios instalados. NOTA: el proveedor cuestiona la importancia de este reporte porque, para instancias a las que puede llegar un actor no autenticado, la misma información está disponible de otras maneras (más complejas), y no existe ningún plan para restringir aún más la información.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-23 CVE Reserved
- 2020-03-23 CVE Published
- 2023-12-09 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/openwrt/luci/issues/3653#issue-567892007 | 2024-08-04 | |
https://github.com/openwrt/luci/issues/3766 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://github.com/openwrt/luci/issues/3563#issuecomment-578522860 | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openwrt Search vendor "Openwrt" | Luci Search vendor "Openwrt" for product "Luci" | git-20.049.11521-bebfe20 Search vendor "Openwrt" for product "Luci" and version "git-20.049.11521-bebfe20" | - |
Affected
| ||||||
Openwrt Search vendor "Openwrt" | Luci Search vendor "Openwrt" for product "Luci" | git-20.078.22902-0ed0d42 Search vendor "Openwrt" for product "Luci" and version "git-20.078.22902-0ed0d42" | - |
Affected
|