CVE-2020-5569
Summary
| CVE | CVE-2020-5569 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-20 08:15:00 UTC |
| Updated | 2020-05-05 19:17:00 UTC |
| Description | An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS, HD-MA10TS), CANVIO SLIM 1TB(HD-SB10TK, HD-SB10TS), and CANVIO SLIM 500GB(HD-SB50GK, HD-SA50GK, HD-SB50GS, HD-SA50GS), and which was downloaded before 2020 May 10. Since it registers Windows services with unquoted file paths, when a registered path contains spaces, and a malicious executable is placed on a certain path, it may be executed with the privilege of the Windows service. |
Risk And Classification
Problem Types: CWE-428
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Toshiba | Hd-ma10ts | - | All | All | All |
| Hardware | Toshiba | Hd-ma10ts | - | All | All | All |
| Hardware | Toshiba | Hd-ma10ty | - | All | All | All |
| Hardware | Toshiba | Hd-ma10ty | - | All | All | All |
| Hardware | Toshiba | Hd-ma20ts | - | All | All | All |
| Hardware | Toshiba | Hd-ma20ts | - | All | All | All |
| Hardware | Toshiba | Hd-ma20ty | - | All | All | All |
| Hardware | Toshiba | Hd-ma20ty | - | All | All | All |
| Hardware | Toshiba | Hd-ma30ts | - | All | All | All |
| Hardware | Toshiba | Hd-ma30ts | - | All | All | All |
| Hardware | Toshiba | Hd-ma30ty | - | All | All | All |
| Hardware | Toshiba | Hd-ma30ty | - | All | All | All |
| Hardware | Toshiba | Hd-mb10ts | - | All | All | All |
| Hardware | Toshiba | Hd-mb10ts | - | All | All | All |
| Hardware | Toshiba | Hd-mb10ty | - | All | All | All |
| Hardware | Toshiba | Hd-mb10ty | - | All | All | All |
| Hardware | Toshiba | Hd-mb20ts | - | All | All | All |
| Hardware | Toshiba | Hd-mb20ts | - | All | All | All |
| Hardware | Toshiba | Hd-mb20ty | - | All | All | All |
| Hardware | Toshiba | Hd-mb20ty | - | All | All | All |
| Hardware | Toshiba | Hd-mb30ts | - | All | All | All |
| Hardware | Toshiba | Hd-mb30ts | - | All | All | All |
| Hardware | Toshiba | Hd-mb30ty | - | All | All | All |
| Hardware | Toshiba | Hd-mb30ty | - | All | All | All |
| Hardware | Toshiba | Hd-sa50gk | - | All | All | All |
| Hardware | Toshiba | Hd-sa50gk | - | All | All | All |
| Hardware | Toshiba | Hd-sa50gs | - | All | All | All |
| Hardware | Toshiba | Hd-sa50gs | - | All | All | All |
| Hardware | Toshiba | Hd-sb10tk | - | All | All | All |
| Hardware | Toshiba | Hd-sb10tk | - | All | All | All |
| Hardware | Toshiba | Hd-sb10ts | - | All | All | All |
| Hardware | Toshiba | Hd-sb10ts | - | All | All | All |
| Hardware | Toshiba | Hd-sb50gk | - | All | All | All |
| Hardware | Toshiba | Hd-sb50gk | - | All | All | All |
| Hardware | Toshiba | Hd-sb50gs | - | All | All | All |
| Hardware | Toshiba | Hd-sb50gs | - | All | All | All |
| Application | Toshiba | Password Tool For Windows | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TDSCSA00699-01: CANVIO™シリーズのWindows 用パスワードツールによって登録されるWindows サービスの実行ファイルパスが引用符で囲まれていない脆弱性について|東芝:パーソナルストレージ | MISC | www.canvio.jp | Vendor Advisory |
| JVN#13467854: Toshiba Electronic Devices & Storage software registers unquoted service paths | MISC | jvn.jp | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.