CVE-2020-13527: CSRF
An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13527?
CVE-2020-13527 is classified as a medium severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2020-13527?
To fix CVE-2020-13527, update the affected Lantronix XPort EDGE firmware to the latest version that mitigates this vulnerability.
Which versions of Lantronix XPort EDGE are affected by CVE-2020-13527?
CVE-2020-13527 affects Lantronix XPort EDGE firmware versions 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12, and 4.2.0.0R7.
Can an attacker exploit CVE-2020-13527 remotely?
Yes, an attacker can exploit CVE-2020-13527 remotely by sending a specially crafted HTTP request.
What impact does CVE-2020-13527 have on system security?
The impact of CVE-2020-13527 is an elevation of privileges, allowing an attacker to gain unauthorized access to system functions.