CVE-2020-16230
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.
Todas las versiones de Ewon Flexy Cozy versiones anteriores a la 14.1, usan comodines tales como (*) bajo los cuales los dominios pueden solicitar recursos. Un atacante con acceso local y privilegios elevados podría inyectar scripts en la configuración Cross-origin Resource Sharing (CORS) que podrían abusar de esta vulnerabilidad, permitiendo al atacante recuperar información confidencial limitada por medio del rastreo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-07-31 CVE Reserved
- 2020-09-18 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-254-03 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hms-networks Search vendor "Hms-networks" | Ewon Flexy Firmware Search vendor "Hms-networks" for product "Ewon Flexy Firmware" | < 14.1 Search vendor "Hms-networks" for product "Ewon Flexy Firmware" and version " < 14.1" | - |
Affected
| in | Hms-networks Search vendor "Hms-networks" | Ewon Flexy Search vendor "Hms-networks" for product "Ewon Flexy" | - | - |
Safe
|
Hms-networks Search vendor "Hms-networks" | Ewon Cosy Firmware Search vendor "Hms-networks" for product "Ewon Cosy Firmware" | < 14.1 Search vendor "Hms-networks" for product "Ewon Cosy Firmware" and version " < 14.1" | - |
Affected
| in | Hms-networks Search vendor "Hms-networks" | Ewon Cosy Search vendor "Hms-networks" for product "Ewon Cosy" | - | - |
Safe
|