CVE-2020-8232
published 2020-08-17CVE-2020-8232: An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.74%
75.1th percentile
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| ui | edgeswitch_firmware | < 1.9.0 | 1.9.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcm4-6gpf-m44q: An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1
ghsa_unreviewed·2022-05-24
CVE-2020-8232 [MEDIUM] CWE-200 GHSA-qcm4-6gpf-m44q: An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability
vendor_msrc·2020-11-10·CVSS 4.3
CVE-2020-17015 [MEDIUM] Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/download/details.aspx?familyid=9a9c9608-da2b-47c6-90f6-20ef0bf01896
Reference: https://support.microsoft.com/help/4486717
Reference: https://www.microsoft.com/download/details.aspx?familyid=466c8e2f-7b95-4a9a-94a7-17ee57f8d01e
Reference: https://support.microsoft.com/help/4486714
Reference: https://www.microsoft.com/download/details.aspx?familyid=53ca5d28-e62f-4adf-8232-01c523626d2f
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695chttps://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821https://www.ui.com/download/edgemaxhttps://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695chttps://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821https://www.ui.com/download/edgemax
2020-08-17
Published