PT-2020-17354 · Mersive · Solstice Pod

Published

2020-12-23

·

Updated

2024-08-04

·

CVE-2020-35587

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Solstice Pod versions prior to 3.0.3
Description The firmware of the affected versions can be easily decompiled or disassembled, and the resulting files contain non-obfuscated code. It is unclear whether the lack of obfuscation directly causes a negative impact or if it only facilitates an attack technique.
Recommendations For versions prior to 3.0.3, update to version 3.0.3 or later to resolve the issue.

Exploit

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2020-35587

Affected Products

Solstice Pod