PT-2020-14153 · Lindy · Lindy 42633 4-Port Usb 2.0 Gigabit Network Server

Denis Werner

·

Published

2020-08-07

·

Updated

2021-07-21

·

CVE-2020-15058

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lindy 42633 4-Port USB 2.0 Gigabit Network Server version 2.078.000
Description The issue allows an attacker on the same network to elevate privileges. This is possible because the administrative password can be discovered by sniffing unencrypted UDP traffic.
Recommendations For version 2.078.000, consider changing the administrative password and enabling encryption for UDP traffic to prevent password sniffing. As a temporary workaround, restrict access to the network to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15058

Affected Products

Lindy 42633 4-Port Usb 2.0 Gigabit Network Server