Vulnerability Description
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Megvii | Koala Firmware | 2.9.1-c3s |
| Megvii | Koala | - |
Related Weaknesses (CWE)
References
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/vulnerability/8137/megviThird Party Advisory
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/vulnerability/8137/megviThird Party Advisory
FAQ
What is CVE-2020-17475?
CVE-2020-17475 is a vulnerability with a CVSS score of 7.5 (HIGH). Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
How severe is CVE-2020-17475?
CVE-2020-17475 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-17475?
Check the references section above for vendor advisories and patch information. Affected products include: Megvii Koala Firmware, Megvii Koala.