CVE Feed

    Dashboard / CVE / CVE-2020-11922

    CVE-2020-11922

    An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the privacy of the end user. The information sent includes the local IP address being used and the SSID of the Wi-Fi network the device is connected to. (Various resources such as wigle.net can be use for mapping of SSIDs to physical locations.)

    Published:Apr 2, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 2, 2021
    EPSS Score:0.00309
    CVSS Score:4.3

    Affected Products

    Vendor
    Wizconnected
    Product
    A60 Colors
    Vendor
    Wizconnected
    Product
    A60 Colors Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High