CVE-2020-21994

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
References
Link Resource
https://cwe.mitre.org/data/definitions/522.html Technical Description
https://www.exploit-db.com/exploits/47819 Exploit Third Party Advisory VDB Entry
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5550.php Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ave:dominaplus:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ave:53ab-wbs_firmware:1.10.62:*:*:*:*:*:*:*
cpe:2.3:h:ave:53ab-wbs:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ave:ts01_firmware:1.0.65:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts01:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ave:ts03x-v_firmware:1.10.45a:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts03x-v:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ave:ts04x-v_firmware:1.10.45a:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts04x-v:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ave:ts05_firmware:1.10.36:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts05:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ave:ts05n-v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts05n-v:-:*:*:*:*:*:*:*

History

26 Oct 2022, 15:15

Type Values Removed Values Added
References (MISC) https://cwe.mitre.org/data/definitions/522.html - (MISC) https://cwe.mitre.org/data/definitions/522.html - Technical Description

10 Jul 2022, 21:15

Type Values Removed Values Added
References
  • (MISC) https://cwe.mitre.org/data/definitions/522.html -

19 May 2021, 19:22

Type Values Removed Values Added
CPE cpe:2.3:a:ave:dominaplus:*:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts05:-:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts01:-:*:*:*:*:*:*:*
cpe:2.3:o:ave:ts05n-v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ave:53ab-wbs:-:*:*:*:*:*:*:*
cpe:2.3:o:ave:ts05_firmware:1.10.36:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts03x-v:-:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts05n-v:-:*:*:*:*:*:*:*
cpe:2.3:o:ave:ts03x-v_firmware:1.10.45a:*:*:*:*:*:*:*
cpe:2.3:o:ave:ts01_firmware:1.0.65:*:*:*:*:*:*:*
cpe:2.3:o:ave:53ab-wbs_firmware:1.10.62:*:*:*:*:*:*:*
cpe:2.3:h:ave:ts04x-v:-:*:*:*:*:*:*:*
cpe:2.3:o:ave:ts04x-v_firmware:1.10.45a:*:*:*:*:*:*:*
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/47819 - (EXPLOIT-DB) https://www.exploit-db.com/exploits/47819 - Exploit, Third Party Advisory, VDB Entry
References (MISC) https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5550.php - (MISC) https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5550.php - Exploit, Third Party Advisory
CWE CWE-522
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8

28 Apr 2021, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-28 15:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-21994

Mitre link : CVE-2020-21994

CVE.ORG link : CVE-2020-21994


JSON object : View

Products Affected

ave

  • ts01_firmware
  • ts03x-v_firmware
  • ts05_firmware
  • ts04x-v_firmware
  • ts05n-v_firmware
  • 53ab-wbs_firmware
  • 53ab-wbs
  • dominaplus
  • ts03x-v
  • ts04x-v
  • ts05
  • ts05n-v
  • ts01
CWE
CWE-522

Insufficiently Protected Credentials