CVE-2020-25195

The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-345-02 Third Party Advisory US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-345-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:6:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:7:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:9:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hosteng:h2-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h2-ecom100:5:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hosteng:h2-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h2-ecom100:8:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hosteng:h4-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h4-ecom100:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:17

Type Values Removed Values Added
References () https://us-cert.cisa.gov/ics/advisories/icsa-20-345-02 - Third Party Advisory, US Government Resource () https://us-cert.cisa.gov/ics/advisories/icsa-20-345-02 - Third Party Advisory, US Government Resource

Information

Published : 2020-12-15 20:15

Updated : 2024-11-21 05:17


NVD link : CVE-2020-25195

Mitre link : CVE-2020-25195

CVE.ORG link : CVE-2020-25195


JSON object : View

Products Affected

hosteng

  • h4-ecom100_firmware
  • h2-ecom100
  • h0-ecom100_firmware
  • h4-ecom100
  • h2-ecom100_firmware
  • h0-ecom100
CWE
CWE-20

Improper Input Validation