Vulnerability Description
A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Flash Memory. The manipulation leads to privilege escalation. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solar-Log | Solar-Log 250 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 250 | - |
| Solar-Log | Solar-Log 300 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 300 | - |
| Solar-Log | Solar-Log 500 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 500 | - |
| Solar-Log | Solar-Log 800E Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 800E | - |
| Solar-Log | Solar-Log 1000 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 1000 | - |
| Solar-Log | Solar-Log 1000 Pm\+ Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 1000 Pm\+ | - |
| Solar-Log | Solar-Log 1200 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 1200 | - |
| Solar-Log | Solar-Log 2000 Firmware | 2.8.4-56 |
| Solar-Log | Solar-Log 2000 | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2017/Mar/58ExploitMailing ListThird Party Advisory
- https://vuldb.com/?id.98935Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Mar/58ExploitMailing ListThird Party Advisory
- https://vuldb.com/?id.98935Third Party Advisory
FAQ
What is CVE-2017-20025?
CVE-2017-20025 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Flash Memory. The manipul...
How severe is CVE-2017-20025?
CVE-2017-20025 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-20025?
Check the references section above for vendor advisories and patch information. Affected products include: Solar-Log Solar-Log 250 Firmware, Solar-Log Solar-Log 250, Solar-Log Solar-Log 300 Firmware, Solar-Log Solar-Log 300, Solar-Log Solar-Log 500 Firmware.