// For flags

CVE-2020-16230

 

Severity Score

2.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.

Todas las versiones de Ewon Flexy Cozy versiones anteriores a la 14.1, usan comodines tales como (*) bajo los cuales los dominios pueden solicitar recursos. Un atacante con acceso local y privilegios elevados podría inyectar scripts en la configuración Cross-origin Resource Sharing (CORS) que podrían abusar de esta vulnerabilidad, permitiendo al atacante recuperar información confidencial limitada por medio del rastreo

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-07-31 CVE Reserved
  • 2020-09-18 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hms-networks
Search vendor "Hms-networks"
Ewon Flexy Firmware
Search vendor "Hms-networks" for product "Ewon Flexy Firmware"
< 14.1
Search vendor "Hms-networks" for product "Ewon Flexy Firmware" and version " < 14.1"
-
Affected
in Hms-networks
Search vendor "Hms-networks"
Ewon Flexy
Search vendor "Hms-networks" for product "Ewon Flexy"
--
Safe
Hms-networks
Search vendor "Hms-networks"
Ewon Cosy Firmware
Search vendor "Hms-networks" for product "Ewon Cosy Firmware"
< 14.1
Search vendor "Hms-networks" for product "Ewon Cosy Firmware" and version " < 14.1"
-
Affected
in Hms-networks
Search vendor "Hms-networks"
Ewon Cosy
Search vendor "Hms-networks" for product "Ewon Cosy"
--
Safe