3.5
CVSSv2

CVE-2020-13527

Published: 18/12/2020 Updated: 07/10/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.5 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lantronix xport_edge_firmware 3.0.0.0

lantronix xport_edge_firmware 3.1.0.0

lantronix xport_edge_firmware 3.4.0.0

lantronix xport_edge_firmware 4.2.0.0

lantronix sgx_firmware 8.7.0.0

lantronix sgx_firmware 8.9.0.0