PT-2020-17068 · Plum · Plum Ik-401
Published
2020-12-08
·
Updated
2021-07-21
·
CVE-2020-28946
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Plum IK-401 devices with firmware before 1.02
Description
The issue is related to an improper webserver configuration, allowing an attacker with network access to the device to obtain the configuration file, including hashed credential data, with a single unauthenticated GET request.
Recommendations
For Plum IK-401 devices with firmware before 1.02, update the firmware to version 1.02 or later to resolve the issue. As a temporary workaround, consider restricting network access to the device to minimize the risk of exploitation.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plum Ik-401