CVE-2020-24395
Summary
| CVE | CVE-2020-24395 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-20 14:15:00 UTC |
| Updated | 2021-06-03 16:43:00 UTC |
| Description | The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can lead to code execution on the device. |
Risk And Classification
Problem Types: CWE-345
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hom.ee | Brain Cube | - | All | All | All |
| Operating System | Hom.ee | Brain Cube Core | 2.28.2 | All | All | All |
| Operating System | Hom.ee | Brain Cube Core | 2.28.4 | All | All | All |
| Operating System | Hom.ee | Brain Cube Firmware | 2.28.2 | All | All | All |
| Operating System | Hom.ee | Brain Cube Firmware | 2.28.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-026.txt | MISC | www.syss.de | |
| Pentest Blog – Aktuelle Themen rund um die SySS und ihre Arbeit | MISC | www.syss.de | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.