First published: Wed Jan 13 2021(Updated: )
Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Univerge Sv9500 Firmware | >=v1<=v7 | |
Nec Univerge Sv9500 | ||
Nec Univerge Sv8500 Firmware | >=s6<=s8 | |
Nec Univerge Sv8500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5686 is a vulnerability in the UNIVERGE SV9500 and SV8500 series that allows an attacker to access the remote system maintenance feature and obtain information by sending a specially crafted request.
The UNIVERGE SV9500 series is affected from V1 to V7, and the SV8500 series is affected from S6 to S8.
CVE-2020-5686 has a severity rating of 7.5, which is considered high.
An attacker can exploit CVE-2020-5686 by sending a specially crafted request to a specific URL to access the remote system maintenance feature and obtain information.
Please refer to the official NEC website and security advisory for information on available fixes or patches for CVE-2020-5686.