CVE-2020-9474
Summary
| CVE | CVE-2020-9474 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-07 21:15:00 UTC |
| Updated | 2020-05-14 14:59:00 UTC |
| Description | The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows remote code execution via the backup functionality in the web frontend. By using an exploit chain, an attacker with access to the network can get root access on the gateway. |
Risk And Classification
Problem Types: CWE-494
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siedle | Sg 150-0 | - | All | All | All |
| Hardware | Siedle | Sg 150-0 | - | All | All | All |
| Operating System | Siedle | Sg 150-0 Firmware | All | All | All | All |
| Operating System | Siedle | Sg 150-0 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Open the Gates! The (In)Security of Cloudless Smart Door Systems – HiSolutions Research | MISC | research.hisolutions.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.