Vulnerability Description
Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.conf URI, when any valid session is running.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sagemcom | F\@St 3486 Router Firmware | 4.109.0 |
| Sagemcom | F\@St 3486 Router | 3.0 |
Related Weaknesses (CWE)
References
- https://medium.com/%40alexandrevvo/improper-access-control-in-the-sagemcom-route
- https://medium.com/%40alexandrevvo/improper-access-control-in-the-sagemcom-route
FAQ
What is CVE-2020-29138?
CVE-2020-29138 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via t...
How severe is CVE-2020-29138?
CVE-2020-29138 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29138?
Check the references section above for vendor advisories and patch information. Affected products include: Sagemcom F\@St 3486 Router Firmware, Sagemcom F\@St 3486 Router.