LOW · 2.3

CVE-2020-16230

All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cr...

Vulnerability Description

All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.

CVSS Score

2.3

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Hms-NetworksEwon Flexy Firmware< 14.1
Hms-NetworksEwon Flexy-
Hms-NetworksEwon Cosy Firmware< 14.1
Hms-NetworksEwon Cosy-

References

FAQ

What is CVE-2020-16230?

CVE-2020-16230 is a vulnerability with a CVSS score of 2.3 (LOW). All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cr...

How severe is CVE-2020-16230?

CVE-2020-16230 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-16230?

Check the references section above for vendor advisories and patch information. Affected products include: Hms-Networks Ewon Flexy Firmware, Hms-Networks Ewon Flexy, Hms-Networks Ewon Cosy Firmware, Hms-Networks Ewon Cosy.