PT-2020-2715 · Nanometrics · Nanometrics Centaur+1

Bytegoblin

·

Published

2020-02-10

·

Updated

2020-05-06

·

CVE-2020-12134

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nanometrics Centaur versions 4.3.23 and earlier Nanometrics TitanSMA versions 4.2.20 and earlier
Description The issue is related to inadequate access control in the syslog log handling. It may allow a remote attacker to elevate privileges by sending specially crafted HTTP packets.
Recommendations For Nanometrics Centaur versions 4.3.23 and earlier, consider restricting access to the syslog log until a patch is available. For Nanometrics TitanSMA versions 4.2.20 and earlier, restrict access to the syslog log to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02791
CVE-2020-12134

Affected Products

Nanometrics Centaur
Nanometrics Titansma