// For flags

CVE-2020-6959

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.

Las siguientes versiones de MAXPRO VMS y NVR, MAXPRO VMS: HNMSWVMS anterior a Versión VMS560 Build 595 T2-Patch, HNMSWVMSLT anterior a Versión VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE anterior a Versión NVR 5.6 Build 595 T2-Patch , MAXPRO NVR SE anterior a Versión NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE anterior a Versión NVR 5.6 Build 595 T2-Patch y MPNVRSWXX anterior a Versión NVR 5.6 Build 595 T2-Patch, son vulnerables a una deserialización no segura de datos no confiables . Un atacante puede ser capaz de modificar remotamente los datos deserializados sin autenticación usando una petición web especialmente diseñada, resultando en una ejecución de código remota.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-14 CVE Reserved
  • 2020-01-22 CVE Published
  • 2024-03-02 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Honeywell
Search vendor "Honeywell"
Maxpro Nvr Xe Firmware
Search vendor "Honeywell" for product "Maxpro Nvr Xe Firmware"
<= 5.6
Search vendor "Honeywell" for product "Maxpro Nvr Xe Firmware" and version " <= 5.6"
-
Affected
in Honeywell
Search vendor "Honeywell"
Maxpro Nvr Xe
Search vendor "Honeywell" for product "Maxpro Nvr Xe"
--
Safe
Honeywell
Search vendor "Honeywell"
Maxpro Nvr Se Firmware
Search vendor "Honeywell" for product "Maxpro Nvr Se Firmware"
<= 5.6
Search vendor "Honeywell" for product "Maxpro Nvr Se Firmware" and version " <= 5.6"
-
Affected
in Honeywell
Search vendor "Honeywell"
Maxpro Nvr Se
Search vendor "Honeywell" for product "Maxpro Nvr Se"
--
Safe
Honeywell
Search vendor "Honeywell"
Maxpro Nvr Pe Firmware
Search vendor "Honeywell" for product "Maxpro Nvr Pe Firmware"
<= 5.6
Search vendor "Honeywell" for product "Maxpro Nvr Pe Firmware" and version " <= 5.6"
-
Affected
in Honeywell
Search vendor "Honeywell"
Maxpro Nvr Pe
Search vendor "Honeywell" for product "Maxpro Nvr Pe"
--
Safe
Honeywell
Search vendor "Honeywell"
Mpnvrswxx Firmware
Search vendor "Honeywell" for product "Mpnvrswxx Firmware"
<= 5.6
Search vendor "Honeywell" for product "Mpnvrswxx Firmware" and version " <= 5.6"
-
Affected
in Honeywell
Search vendor "Honeywell"
Mpnvrswxx
Search vendor "Honeywell" for product "Mpnvrswxx"
--
Safe
Honeywell
Search vendor "Honeywell"
Hnmswvms Firmware
Search vendor "Honeywell" for product "Hnmswvms Firmware"
<= vms560
Search vendor "Honeywell" for product "Hnmswvms Firmware" and version " <= vms560"
-
Affected
in Honeywell
Search vendor "Honeywell"
Hnmswvms
Search vendor "Honeywell" for product "Hnmswvms"
--
Safe
Honeywell
Search vendor "Honeywell"
Hnmswvmslt Firmware
Search vendor "Honeywell" for product "Hnmswvmslt Firmware"
<= vms560
Search vendor "Honeywell" for product "Hnmswvmslt Firmware" and version " <= vms560"
-
Affected
in Honeywell
Search vendor "Honeywell"
Hnmswvmslt
Search vendor "Honeywell" for product "Hnmswvmslt"
--
Safe