Resource management error in eUDC660 - CVE-2020-9206

 

Resource management error in eUDC660 - CVE-2020-9206

Published: February 3, 2021


Vulnerability identifier: #VU50287
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9206
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to improper management of internal resources within the application. A local administrator can pass specially crafted data to the application, obtain the key file and decrypt data, affecting confidentiality, integrity, and availability of the device.


Affected software

eUDC660

How to mitigate CVE-2020-9206

Install updates from vendor's website.

eUDC660 - update to V100R006C00SPC107

External References

Related Security Bulletins