CVE-2020-6960
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.
Las siguientes versiones de MAXPRO VMS y NVR, MAXPRO VMS: HNMSWVMS anterior a Versión VMS560 Build 595 T2-Patch, HNMSWVMSLT anterior a Versión VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE anterior a Versión NVR 5.6 Build 595 T2-Patch , MAXPRO NVR SE anterior a Versión NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE anterior a Versión NVR 5.6 Build 595 T2-Patch y MPNVRSWXX anterior a Versión NVR 5.6 Build 595 T2-Patch, contienen una vulnerabilidad de inyección SQL que podría otorgar a un atacante un acceso no autenticado remoto en la interfaz de usuario web con privilegios de nivel de administrador.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-14 CVE Reserved
- 2020-01-22 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-021-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Honeywell Search vendor "Honeywell" | Maxpro Nvr Xe Firmware Search vendor "Honeywell" for product "Maxpro Nvr Xe Firmware" | <= 5.6 Search vendor "Honeywell" for product "Maxpro Nvr Xe Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Maxpro Nvr Xe Search vendor "Honeywell" for product "Maxpro Nvr Xe" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Maxpro Nvr Se Firmware Search vendor "Honeywell" for product "Maxpro Nvr Se Firmware" | <= 5.6 Search vendor "Honeywell" for product "Maxpro Nvr Se Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Maxpro Nvr Se Search vendor "Honeywell" for product "Maxpro Nvr Se" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Maxpro Nvr Pe Firmware Search vendor "Honeywell" for product "Maxpro Nvr Pe Firmware" | <= 5.6 Search vendor "Honeywell" for product "Maxpro Nvr Pe Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Maxpro Nvr Pe Search vendor "Honeywell" for product "Maxpro Nvr Pe" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Mpnvrswxx Firmware Search vendor "Honeywell" for product "Mpnvrswxx Firmware" | <= 5.6 Search vendor "Honeywell" for product "Mpnvrswxx Firmware" and version " <= 5.6" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Mpnvrswxx Search vendor "Honeywell" for product "Mpnvrswxx" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Hnmswvms Firmware Search vendor "Honeywell" for product "Hnmswvms Firmware" | <= vms560 Search vendor "Honeywell" for product "Hnmswvms Firmware" and version " <= vms560" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Hnmswvms Search vendor "Honeywell" for product "Hnmswvms" | - | - |
Safe
|
Honeywell Search vendor "Honeywell" | Hnmswvmslt Firmware Search vendor "Honeywell" for product "Hnmswvmslt Firmware" | <= vms560 Search vendor "Honeywell" for product "Hnmswvmslt Firmware" and version " <= vms560" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Hnmswvmslt Search vendor "Honeywell" for product "Hnmswvmslt" | - | - |
Safe
|