Back to overview

CVE-2020-12030

CRITICAL
10.0
CVSS 3.1
Description
There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.

Metadata

CVE ID
CVE-2020-12030
State
PUBLISHED
Assigner
icscert
Reserved
2020-04-21 00:00 UTC
Published
2021-09-29 19:36 UTC
Last updated
2024-08-04 11:48 UTC
Primary CWE
CWE-284
IMPROPER ACCESS CONTROL CWE-284
Vendor / Product
Emerson / Wireless 1410 Gateway
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (3)
VendorProductPlatformVersions
Emerson Wireless 1410 Gateway 4.6.43 ≤ 4.7.84
Emerson Wireless 1420 Gateway 4.6.43 ≤ 4.7.84
Emerson Wireless 1552WU Gateway 4.6.43 ≤ 4.7.84
Weakness (CWE)
CWESourceDescription
CWE-284 cna IMPROPER ACCESS CONTROL CWE-284
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview