The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Honeywell
Subscribe
|
Hnmswvms
Subscribe
Hnmswvms Firmware
Subscribe
Hnmswvmslt
Subscribe
Hnmswvmslt Firmware
Subscribe
Maxpro Nvr Pe
Subscribe
Maxpro Nvr Pe Firmware
Subscribe
Maxpro Nvr Se
Subscribe
Maxpro Nvr Se Firmware
Subscribe
Maxpro Nvr Xe
Subscribe
Maxpro Nvr Xe Firmware
Subscribe
Mpnvrswxx
Subscribe
Mpnvrswxx Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28099 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-20-021-01 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T09:18:02.463Z
Reserved: 2020-01-14T00:00:00
Link: CVE-2020-6959
No data.
Status : Modified
Published: 2020-01-22T15:15:11.270
Modified: 2024-11-21T05:36:23.380
Link: CVE-2020-6959
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD