Description
UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.
No analysis available yet.
Remediation
Vendor Solution
Update to V1.5.0 or later version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-25185 | UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-3452-937d6-1.html |
|
History
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory. | UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory. |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T02:16:00.930Z
Reserved: 2019-12-20T00:00:00.000Z
Link: CVE-2020-3920
No data.
Status : Modified
Published: 2020-03-27T04:15:10.770
Modified: 2024-11-21T05:31:57.603
Link: CVE-2020-3920
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD