CVE-2020-12681: High severity 3xlogic infinias eidc32 firmware vulnerability
Published Jul 26, 2021
·Updated
Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/control the channel by which door lock policies are applied.
Affected Software
2 affected components
3xLOGIC Infinias Eidc32 Firmware<=3.4.125
3xLOGIC Infinias eIDC32
Event History
Jul 26, 2021
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-12681.
2
What is the affected software for this vulnerability?
The affected software is 3xlogic Infinias eIDC32 firmware version up to and including 3.4.125.
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by intercepting/controling the channel by which door lock policies are applied.
4
Is there a fix available for this vulnerability?
Yes, updating to version 3.9 of the Infinias eIDC32 firmware will fix this vulnerability.
5
What is the severity rating of CVE-2020-12681?
The severity rating of CVE-2020-12681 is high, with a CVSS score of 7.5.