Incorrect Comparison in DAP-2610 - CVE-2020-8862

 

Incorrect Comparison in DAP-2610 - CVE-2020-8862

Published: February 24, 2020


Vulnerability identifier: #VU25541
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8862
CWE-ID: CWE-697
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the lack of proper password checking. A remote attacker on the local network can affect the device that could cause the device to malfunction or disclose information.

An attacker can leverage this vulnerability to execute arbitrary code in the context of root.


Affected software

DAP-2610

How to mitigate CVE-2020-8862

Install updates from vendor's website.

DAP-2610 - update to v2.01_K2HE_HOTFIX

External References

Related Security Bulletins