CVE-2020-22002
Summary
| CVE | CVE-2020-22002 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-29 15:15:00 UTC |
| Updated | 2021-05-05 17:56:00 UTC |
| Description | An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Inim | Smartliving 10100l | - | All | All | All |
| Hardware | Inim | Smartliving 10100lg3 | - | All | All | All |
| Operating System | Inim | Smartliving 10100lg3 Firmware | - | All | All | All |
| Operating System | Inim | Smartliving 10100l Firmware | - | All | All | All |
| Hardware | Inim | Smartliving 1050 | - | All | All | All |
| Hardware | Inim | Smartliving 1050g3 | - | All | All | All |
| Operating System | Inim | Smartliving 1050g3 Firmware | - | All | All | All |
| Operating System | Inim | Smartliving 1050 Firmware | - | All | All | All |
| Hardware | Inim | Smartliving 505 | - | All | All | All |
| Operating System | Inim | Smartliving 505 Firmware | - | All | All | All |
| Hardware | Inim | Smartliving 515 | - | All | All | All |
| Operating System | Inim | Smartliving 515 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | |
| Zero Science Lab » Inim Electronics Smartliving SmartLAN/G/SI <=6.x Unauthenticated SSRF | MISC | www.zeroscience.mk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.