Vulnerability Description
A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Onkyo | Tx-Nr585 Firmware | 1000-0000-000-0008-0000 |
| Onkyo | Tx-Nr585 | - |
Related Weaknesses (CWE)
References
- https://blog.spookysec.net/onkyo-lfi/ExploitThird Party Advisory
- https://blog.spookysec.net/onkyo-lfi/ExploitThird Party Advisory
FAQ
What is CVE-2020-12447?
CVE-2020-12447 is a vulnerability with a CVSS score of 7.5 (HIGH). A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as de...
How severe is CVE-2020-12447?
CVE-2020-12447 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12447?
Check the references section above for vendor advisories and patch information. Affected products include: Onkyo Tx-Nr585 Firmware, Onkyo Tx-Nr585.