CVE-2020-11918

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file.
References
Link Resource
https://seclists.org/fulldisclosure/2024/Jul/14 Mailing List Third Party Advisory Exploit
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:svakom:svakom_siime_eye_firmware:14.1.00000001.3.330.0.0.3.14:*:*:*:*:*:*:*
cpe:2.3:h:svakom:svakom_siime_eye:-:*:*:*:*:*:*:*

History

24 Apr 2025, 13:42

Type Values Removed Values Added
References () https://seclists.org/fulldisclosure/2024/Jul/14 - () https://seclists.org/fulldisclosure/2024/Jul/14 - Mailing List, Third Party Advisory, Exploit
CPE cpe:2.3:h:svakom:svakom_siime_eye:-:*:*:*:*:*:*:*
cpe:2.3:o:svakom:svakom_siime_eye_firmware:14.1.00000001.3.330.0.0.3.14:*:*:*:*:*:*:*
First Time Svakom svakom Siime Eye
Svakom
Svakom svakom Siime Eye Firmware

08 Nov 2024, 19:01

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Siime Eye 14.1.00000001.3.330.0.0.3.14. Cuando se crea un archivo de copia de seguridad a través de la interfaz web, la información sobre todos los usuarios, incluidas las contraseñas, se puede encontrar en texto plano en el archivo de copia de seguridad. Un atacante capaz de acceder a la interfaz web puede crear el archivo de copia de seguridad.

07 Nov 2024, 21:35

Type Values Removed Values Added
CWE CWE-312
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

07 Nov 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 18:15

Updated : 2025-04-24 13:42


NVD link : CVE-2020-11918

Mitre link : CVE-2020-11918

CVE.ORG link : CVE-2020-11918


JSON object : View

Products Affected

svakom

  • svakom_siime_eye
  • svakom_siime_eye_firmware
CWE
CWE-312

Cleartext Storage of Sensitive Information