MEDIUM · 5.9

CVE-2020-35584

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's net...

Vulnerability Description

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MersiveSolstice Pod Firmware< 3.0.3
MersiveSolstice Pod-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-35584?

CVE-2020-35584 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's net...

How severe is CVE-2020-35584?

CVE-2020-35584 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-35584?

Check the references section above for vendor advisories and patch information. Affected products include: Mersive Solstice Pod Firmware, Mersive Solstice Pod.