PT-2020-14157 · Digitus · Digitus Da-70254

Denis Werner

·

Published

2020-08-07

·

Updated

2021-07-21

·

CVE-2020-15062

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DIGITUS DA-70254 4-Port Gigabit Network Hub version 2.073.000.E0008
Description The issue allows an attacker on the same network to elevate privileges. This is possible because the administrative password can be discovered by sniffing unencrypted UDP traffic.
Recommendations For version 2.073.000.E0008, consider restricting access to the administrative interface until a patch is available. As a temporary workaround, avoid using unencrypted UDP traffic for administrative tasks.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15062

Affected Products

Digitus Da-70254