CVE-2020-6959
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.
Las siguientes versiones de MAXPRO VMS y NVR, MAXPRO VMS: HNMSWVMS anterior a Versión VMS560 Build 595 T2-Patch, HNMSWVMSLT anterior a Versión VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE anterior a Versión NVR 5.6 Build 595 T2-Patch , MAXPRO NVR SE anterior a Versión NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE anterior a Versión NVR 5.6 Build 595 T2-Patch y MPNVRSWXX anterior a Versión NVR 5.6 Build 595 T2-Patch, son vulnerables a una deserialización no segura de datos no confiables . Un atacante puede ser capaz de modificar remotamente los datos deserializados sin autenticación usando una petición web especialmente diseñada, resultando en una ejecución de código remota.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-14 CVE Reserved
- 2020-01-22 CVE Published
- 2024-03-02 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-021-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Honeywell Search vendor "Honeywell" | Maxpro Nvr Xe Firmware Search vendor "Honeywell" for product "Maxpro Nvr Xe Firmware" | <= 5.6 Search vendor "Honeywell" for product "Maxpro Nvr Xe Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Maxpro Nvr Xe Search vendor "Honeywell" for product "Maxpro Nvr Xe" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Maxpro Nvr Se Firmware Search vendor "Honeywell" for product "Maxpro Nvr Se Firmware" | <= 5.6 Search vendor "Honeywell" for product "Maxpro Nvr Se Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Maxpro Nvr Se Search vendor "Honeywell" for product "Maxpro Nvr Se" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Maxpro Nvr Pe Firmware Search vendor "Honeywell" for product "Maxpro Nvr Pe Firmware" | <= 5.6 Search vendor "Honeywell" for product "Maxpro Nvr Pe Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Maxpro Nvr Pe Search vendor "Honeywell" for product "Maxpro Nvr Pe" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Mpnvrswxx Firmware Search vendor "Honeywell" for product "Mpnvrswxx Firmware" | <= 5.6 Search vendor "Honeywell" for product "Mpnvrswxx Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Mpnvrswxx Search vendor "Honeywell" for product "Mpnvrswxx" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Hnmswvms Firmware Search vendor "Honeywell" for product "Hnmswvms Firmware" | <= vms560 Search vendor "Honeywell" for product "Hnmswvms Firmware" and version " <= vms560" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Hnmswvms Search vendor "Honeywell" for product "Hnmswvms" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Hnmswvmslt Firmware Search vendor "Honeywell" for product "Hnmswvmslt Firmware" | <= vms560 Search vendor "Honeywell" for product "Hnmswvmslt Firmware" and version " <= vms560" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Hnmswvmslt Search vendor "Honeywell" for product "Hnmswvmslt" | - | - |
Safe
|