PT-2020-14157 · Digitus · Digitus Da-70254
Denis Werner
·
Published
2020-08-07
·
Updated
2021-07-21
·
CVE-2020-15062
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DIGITUS DA-70254 4-Port Gigabit Network Hub version 2.073.000.E0008
Description
The issue allows an attacker on the same network to elevate privileges. This is possible because the administrative password can be discovered by sniffing unencrypted UDP traffic.
Recommendations
For version 2.073.000.E0008, consider restricting access to the administrative interface until a patch is available. As a temporary workaround, avoid using unencrypted UDP traffic for administrative tasks.
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Digitus Da-70254