CVE-2020-10176: Code Injection
Published May 7, 2020
·Updated
ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43p1 devices allow Eval Injection of commands.
Affected Software
4 affected components
Assaabloy Yale Wipc-301w Firmware>=2.x.2.29<2.x.2.43
Assaabloy Yale Wipc-301w Firmware=2.x.2.43
Assaabloy Yale Wipc-301w Firmware=2.x.2.43-p1
Assaabloy Yale Wipc-301w
Event History
May 7, 2020
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10176?
CVE-2020-10176 is a vulnerability that allows Eval Injection of commands in ASSA ABLOY Yale WIPC-301W devices running firmware versions 2.x.2.29 through 2.x.2.43_p1.
2
How severe is CVE-2020-10176?
CVE-2020-10176 has a severity rating of 9.8, which is classified as critical.
3
What is the affected software for CVE-2020-10176?
The affected software for CVE-2020-10176 is ASSA ABLOY Yale WIPC-301W devices running firmware versions 2.x.2.29 through 2.x.2.43_p1.
4
How can I fix CVE-2020-10176?
To fix CVE-2020-10176, update the firmware on your ASSA ABLOY Yale WIPC-301W device to a version that is not affected by this vulnerability.
5
Where can I find more information about CVE-2020-10176?
You can find more information about CVE-2020-10176 in the following references: [link1] [link2].