CVE-2020-28993
Summary
| CVE | CVE-2020-28993 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-01 16:15:00 UTC |
| Updated | 2020-12-02 16:41:00 UTC |
| Description | A Directory Traversal vulnerability exists in ATX miniCMTS200a Broadband Gateway through 2.0 and Pico CMTS through 2.0. Successful exploitation of this vulnerability would allow an unauthenticated attacker to retrieve administrator credentials by sending a malicious POST request. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Atx | Minicmts200a | - | All | All | All |
| Hardware | Atx | Minicmts200a | - | All | All | All |
| Operating System | Atx | Minicmts200a Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| miniCMTS200a Broadband Gateway - ATX Networks | MISC | atx.com | Product, Vendor Advisory |
| ATX MiniCMTS200a Broadband Gateway 2.0 - Credential Disclosure - Hardware webapps Exploit | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.