PT-2020-12389 · Openwrt · Openwrt Luci

Ghost

·

Published

2020-03-23

·

Updated

2024-08-04

·

CVE-2020-10871

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenWrt LuCI versions git-20.x
Description The issue allows remote unauthenticated attackers to retrieve the list of installed packages and services. The vendor disputes the significance of this report, stating that the same information is available in other, more complex ways for instances reachable by an unauthenticated actor, and there is no plan to restrict the information further.
Recommendations For OpenWrt LuCI versions git-20.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2020-10871

Affected Products

Openwrt Luci