CVE-2020-10922

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of proper input validation prior to further processing user requests. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-10527.
References
Link Resource
https://www.zerodayinitiative.com/advisories/ZDI-20-809/ Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:automationdirect:c-more_hmi_ea9_firmware:6.52:*:*:*:*:*:*:*
OR cpe:2.3:h:automationdirect:ea9-pgmsw:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-rhmi:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t10cl:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t10wcl:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t12cl:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t15cl:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t15cl-r:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t6cl:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t6cl-r:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t7cl:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t7cl-r:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:ea9-t8cl:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-07-23 16:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-10922

Mitre link : CVE-2020-10922

CVE.ORG link : CVE-2020-10922


JSON object : View

Products Affected

automationdirect

  • ea9-t6cl-r
  • ea9-t7cl
  • ea9-rhmi
  • ea9-pgmsw
  • ea9-t12cl
  • ea9-t15cl
  • c-more_hmi_ea9_firmware
  • ea9-t15cl-r
  • ea9-t10cl
  • ea9-t6cl
  • ea9-t7cl-r
  • ea9-t10wcl
  • ea9-t8cl
CWE
CWE-20

Improper Input Validation