CVE-2019-20026: High severity nec sv9100 vulnerability
Published Jul 29, 2020
·Updated
The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.
Affected Software
2 affected components
NEC Sv9100 Firmware>=7.0
NEC SV9100
Event History
Jul 29, 2020
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20026?
CVE-2019-20026 is a vulnerability in NEC SV9100 software releases 7.0 or higher that allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.
2
How severe is CVE-2019-20026?
CVE-2019-20026 has a severity rating of 7.5 (high).
3
Which software versions are affected by CVE-2019-20026?
NEC SV9100 software releases 7.0 or higher are affected by CVE-2019-20026.
4
How can the vulnerability in CVE-2019-20026 be exploited?
The vulnerability in CVE-2019-20026 can be exploited by unauthenticated remote attackers via a crafted request.
5
Is NEC SV9100 software vulnerable to CVE-2019-20026?
No, NEC SV9100 software itself is not vulnerable to CVE-2019-20026.