// For flags

CVE-2020-29379

 

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating the firmware, the update script starts a telnetd -l /bin/sh process that does not require authentication for TELNET access.

Se detectó un problema en los dispositivos OLT V-SOL V1600D4L versión V1.01.49 y V1600D-MINI versión V1.01.48. Durante el proceso de actualización del firmware, el script de actualización inicia un proceso telnetd -l /bin/sh que no requiere autenticación para el acceso TELNET

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-11-29 CVE Reserved
  • 2020-11-29 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vsolcn
Search vendor "Vsolcn"
V1600d4l Firmware
Search vendor "Vsolcn" for product "V1600d4l Firmware"
1.01.49
Search vendor "Vsolcn" for product "V1600d4l Firmware" and version "1.01.49"
-
Affected
in Vsolcn
Search vendor "Vsolcn"
V1600d4l
Search vendor "Vsolcn" for product "V1600d4l"
--
Safe
Vsolcn
Search vendor "Vsolcn"
V1600d-mini Firmware
Search vendor "Vsolcn" for product "V1600d-mini Firmware"
1.01.48
Search vendor "Vsolcn" for product "V1600d-mini Firmware" and version "1.01.48"
-
Affected
in Vsolcn
Search vendor "Vsolcn"
V1600d-mini
Search vendor "Vsolcn" for product "V1600d-mini"
--
Safe