PT-2020-17108 · Panasonic · Panasonic Security System Wv-S2231L

Published

2020-12-28

·

Updated

2020-12-30

·

CVE-2020-29194

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Panasonic Security System WV-S2231L version 4.25
Description The issue allows for a denial of service of the admin control panel, which will require a physical reset to restore administrative control. This can be achieved via Randomnum=99AC8CEC6E845B28 and mode=1 in a POST request to the "cgi-bin/set factory" URI.
Recommendations For Panasonic Security System WV-S2231L version 4.25, as a temporary workaround, consider restricting access to the "cgi-bin/set factory" URI to minimize the risk of exploitation. Avoid using the Randomnum and mode parameters in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-29194

Affected Products

Panasonic Security System Wv-S2231L