CVE-2020-36283
HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the device. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
Published:Mar 24, 2021
Last Modified:Nov 21, 2024
EPS:Mar 24, 2021
EPSS Score:0.00214
CVSS Score:9.6
Affected Products
Vendor
Product
Action
Vendor
Hidglobal
Product
Omnikey 5127
Hidglobal
Omnikey 5127
Vendor
Hidglobal
Product
Omnikey 5127 Firmware
Hidglobal
Omnikey 5127 Firmware
Vendor
Hidglobal
Product
Omnikey 5427
Hidglobal
Omnikey 5427
Vendor
Hidglobal
Product
Omnikey 5427 Firmware
Hidglobal
Omnikey 5427 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
