Improper access control in Emerson products - CVE-2020-12030

 

Improper access control in Emerson products - CVE-2020-12030

Published: May 15, 2020


Vulnerability identifier: #VU27948
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12030
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway. A remote attacker can issue specific commands to the gateway, which could then be forwarded on to the end user's wireless devices.


Affected software

Wireless 1410 Gateway
Wireless 1420 Gateway
Wireless 1552WU Gateway

How to mitigate CVE-2020-12030

Install updates from vendor's website.

Wireless 1410 Gateway - update to 4.7.90
Wireless 1420 Gateway - update to 4.7.90
Wireless 1552WU Gateway - update to 4.7.90

External References

Related Security Bulletins