ID

VAR-202008-0979


CVE

CVE-2020-8232


TITLE

EdgeMax EdgeSwitch Information leakage vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2020-009587

DESCRIPTION

An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages. EdgeMax EdgeSwitch There is an information leakage vulnerability in the firmware.Information may be obtained. Ubiquiti Networks EdgeMAX EdgeSwitch is a PoE+ Gigabit switch from Ubiquiti Networks

Trust: 2.16

sources: NVD: CVE-2020-8232 // JVNDB: JVNDB-2020-009587 // CNVD: CNVD-2020-46805

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-46805

AFFECTED PRODUCTS

vendor:uimodel:edgeswitchscope:ltversion:1.9.0

Trust: 1.0

vendor:ubiquitimodel:edgeswitchscope: - version: -

Trust: 0.8

vendor:ubiquitimodel:networks ubiquiti networks edgemax edgeswitchscope:eqversion:1.9.0

Trust: 0.6

sources: CNVD: CNVD-2020-46805 // JVNDB: JVNDB-2020-009587 // NVD: CVE-2020-8232

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8232
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-009587
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-46805
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202008-857
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-8232
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-009587
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-46805
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-8232
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009587
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-46805 // JVNDB: JVNDB-2020-009587 // CNNVD: CNNVD-202008-857 // NVD: CVE-2020-8232

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2020-009587 // NVD: CVE-2020-8232

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202008-857

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202008-857

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009587

PATCH

title:Security advisory bulletin 014url:https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821

Trust: 0.8

title:EdgeMAX EdgeSwitch Firmware v1.9.1url:https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695c

Trust: 0.8

title:EdgeMAXurl:https://www.ui.com/download/edgemax/

Trust: 0.8

title:Patch for EdgeSwitch firmware information disclosure vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/231064

Trust: 0.6

title:Ubiquiti Network EdgeMax EdgeSwitch Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=126544

Trust: 0.6

sources: CNVD: CNVD-2020-46805 // JVNDB: JVNDB-2020-009587 // CNNVD: CNNVD-202008-857

EXTERNAL IDS

db:NVDid:CVE-2020-8232

Trust: 3.0

db:JVNDBid:JVNDB-2020-009587

Trust: 0.8

db:CNVDid:CNVD-2020-46805

Trust: 0.6

db:NSFOCUSid:48739

Trust: 0.6

db:CNNVDid:CNNVD-202008-857

Trust: 0.6

sources: CNVD: CNVD-2020-46805 // JVNDB: JVNDB-2020-009587 // CNNVD: CNNVD-202008-857 // NVD: CVE-2020-8232

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-8232

Trust: 2.0

url:https://community.ui.com/releases/security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821

Trust: 1.6

url:https://community.ui.com/releases/edgemax-edgeswitch-firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695c

Trust: 1.6

url:https://www.ui.com/download/edgemax

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8232

Trust: 0.8

url:http://www.nsfocus.net/vulndb/48739

Trust: 0.6

sources: CNVD: CNVD-2020-46805 // JVNDB: JVNDB-2020-009587 // CNNVD: CNNVD-202008-857 // NVD: CVE-2020-8232

SOURCES

db:CNVDid:CNVD-2020-46805
db:JVNDBid:JVNDB-2020-009587
db:CNNVDid:CNNVD-202008-857
db:NVDid:CVE-2020-8232

LAST UPDATE DATE

2024-11-23T23:07:53.754000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-46805date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009587date:2020-11-19T05:37:46
db:CNNVDid:CNNVD-202008-857date:2020-09-14T00:00:00
db:NVDid:CVE-2020-8232date:2024-11-21T05:38:33.310

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-46805date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009587date:2020-11-19T05:37:46
db:CNNVDid:CNNVD-202008-857date:2020-08-17T00:00:00
db:NVDid:CVE-2020-8232date:2020-08-17T16:15:13.780