CVE-2020-25195

The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-345-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:6:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:7:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:9:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hosteng:h2-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h2-ecom100:5:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hosteng:h2-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h2-ecom100:8:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hosteng:h4-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h4-ecom100:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-12-15 20:15

Updated : 2024-02-04 21:23


NVD link : CVE-2020-25195

Mitre link : CVE-2020-25195

CVE.ORG link : CVE-2020-25195


JSON object : View

Products Affected

hosteng

  • h0-ecom100
  • h0-ecom100_firmware
  • h2-ecom100
  • h2-ecom100_firmware
  • h4-ecom100
  • h4-ecom100_firmware
CWE
CWE-20

Improper Input Validation