CVE Feed

    Dashboard / CVE / CVE-2020-22002

    CVE-2020-22002

    An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host.

    Published:Apr 29, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 29, 2021
    EPSS Score:0.00552
    CVSS Score:7.5

    Affected Products

    Vendor
    Inim
    Product
    Smartliving 10100l
    Vendor
    Inim
    Product
    Smartliving 10100l Firmware
    Vendor
    Inim
    Product
    Smartliving 10100lg3
    Vendor
    Inim
    Product
    Smartliving 10100lg3 Firmware
    Vendor
    Inim
    Product
    Smartliving 1050
    Vendor
    Inim
    Product
    Smartliving 1050 Firmware
    Vendor
    Inim
    Product
    Smartliving 1050g3
    Vendor
    Inim
    Product
    Smartliving 1050g3 Firmware
    Vendor
    Inim
    Product
    Smartliving 505
    Vendor
    Inim
    Product
    Smartliving 505 Firmware
    Vendor
    Inim
    Product
    Smartliving 515
    Vendor
    Inim
    Product
    Smartliving 515 Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High