MEDIUM · 6.2

CVE-2020-15858

Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate attackers. The directory path access check of the internal flash file system can be ...

Vulnerability Description

Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate attackers. The directory path access check of the internal flash file system can be circumvented. This flash file system can store application-specific data and data needed for customer Java applications, TLS and OTAP (Java over-the-air-provisioning) functionality. The affected products and releases are: BGS5 up to and including SW RN 02.000 / ARN 01.001.06 EHSx and PDSx up to and including SW RN 04.003 / ARN 01.000.04 ELS61 up to and including SW RN 02.002 / ARN 01.000.04 ELS81 up to and including SW RN 05.002 / ARN 01.000.04 PLS62 up to and including SW RN 02.000 / ARN 01.000.04

CVSS Score

6.2

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
LOW

Affected Products

VendorProductVersions
ThalesgroupBgs5 Firmware<= rn_02.000_\/_arn_01.001.06
ThalesgroupBgs5-
ThalesgroupEhs5 Firmware<= rn_04.003_\/_arn_01.000.04
ThalesgroupEhs5-
ThalesgroupEhs8 Firmware<= rn_04.003_\/_arn_01.000.04
ThalesgroupEhs8-
ThalesgroupEhs6 Firmware<= rn_04.003_\/_arn_01.000.04
ThalesgroupEhs6-
ThalesgroupPds5 Firmware<= rn_04.003_\/_arn_01.000.04
ThalesgroupPds5-
ThalesgroupPds6 Firmware<= rn_04.003_\/_arn_01.000.04
ThalesgroupPds6-
ThalesgroupEls61 Firmware<= rn_02.002_\/_arn_01.000.04
ThalesgroupEls61-
ThalesgroupEls81 Firmware<= rn_05.002_\/_arn_01.000.04
ThalesgroupEls81-
ThalesgroupPls62 Firmware<= rn_02.000_\/_arn_01.000.04
ThalesgroupPls62-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15858?

CVE-2020-15858 is a vulnerability with a CVSS score of 6.2 (MEDIUM). Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate attackers. The directory path access check of the internal flash file system can be ...

How severe is CVE-2020-15858?

CVE-2020-15858 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-15858?

Check the references section above for vendor advisories and patch information. Affected products include: Thalesgroup Bgs5 Firmware, Thalesgroup Bgs5, Thalesgroup Ehs5 Firmware, Thalesgroup Ehs5, Thalesgroup Ehs8 Firmware.