PT-2021-9465 · 3Xlogic · 3Xlogic Infinias Eidc32

Published

2021-07-26

·

Updated

2021-08-05

·

CVE-2020-12681

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions 3xLogic Infinias eIDC32 devices through 3.4.125
Description The issue is related to missing TLS certificate validation, which allows an attacker to intercept or control the channel used for applying door lock policies.
Recommendations For versions through 3.4.125, consider disabling TLS connections until a patch is available, and restrict access to the door lock policy application channel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12681

Affected Products

3Xlogic Infinias Eidc32