CVE-2020-8232: Infoleak
Published Aug 17, 2020
·Updated
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
Affected Software
12 affected components
UI Edgeswitch Firmware<1.9.0
UI Ep-16-xg
UI Ep-s16
UI Es-12f
UI Es-16-150w
UI Es-24-250w
UI Es-24-500w
UI Es-24-lite
UI Es-48-500w
UI Es-48-750w
UI Es-48-lite
UI Es-8-150w
Remediation
Event History
Aug 17, 2020
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-8232?
CVE-2020-8232 is an information disclosure vulnerability that exists in EdgeMax EdgeSwitch firmware v1.9.0.
2
How does CVE-2020-8232 impact EdgeMax EdgeSwitch firmware v1.9.0?
CVE-2020-8232 allows read-only users to obtain unauthorized information through SNMP community pages.
3
What software versions are affected by CVE-2020-8232?
EdgeMax EdgeSwitch firmware v1.9.0 is the only affected software version.
4
What is the severity of CVE-2020-8232?
CVE-2020-8232 has a severity value of 6.5 out of 10.
5
How can I fix CVE-2020-8232?
To fix CVE-2020-8232, it is recommended to update to EdgeMax EdgeSwitch firmware version 1.9.1 or higher.