Vulnerability Description
A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unknown processing of the component Network Config. The manipulation leads to privilege escalation. The attack may be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solar-Log | Solar-Log 250 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 250 | - |
| Solar-Log | Solar-Log 300 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 300 | - |
| Solar-Log | Solar-Log 500 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 500 | - |
| Solar-Log | Solar-Log 800E Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 800E | - |
| Solar-Log | Solar-Log 1000 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 1000 | - |
| Solar-Log | Solar-Log 1000 Pm\+ Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 1000 Pm\+ | - |
| Solar-Log | Solar-Log 1200 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 1200 | - |
| Solar-Log | Solar-Log 2000 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 2000 | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2017/Mar/58ExploitMailing ListThird Party Advisory
- https://vuldb.com/?id.98933Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Mar/58ExploitMailing ListThird Party Advisory
- https://vuldb.com/?id.98933Third Party Advisory
FAQ
What is CVE-2017-20023?
CVE-2017-20023 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unknown processing of the component Network Config. The manipulation leads to privil...
How severe is CVE-2017-20023?
CVE-2017-20023 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-20023?
Check the references section above for vendor advisories and patch information. Affected products include: Solar-Log Solar-Log 250 Firmware, Solar-Log Solar-Log 250, Solar-Log Solar-Log 300 Firmware, Solar-Log Solar-Log 300, Solar-Log Solar-Log 500 Firmware.