« Volver al listado

CVE-2020-5633

Estado: ModificadaCrítica (9.8)—

Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to bypass authentication and then obtain/modify BMC setting information, obtain monitoring information, or reboot/shut down the vulnerable product via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5633",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:C",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 8.5,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "NEC Corporation",
          "product": "Multiple NEC products where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied",
          "versions": [
            {
              "status": "affected",
              "version": "Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-13T10:15:14.830",
  "references": [
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv21-002.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN38752718/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.support.nec.co.jp/View.aspx?id=9010108754",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv21-002.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN38752718/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.support.nec.co.jp/View.aspx?id=9010108754",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to bypass authentication and then obtain/modify BMC setting information, obtain monitoring information, or reboot/shut down the vulnerable product via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Múltiples productos NEC (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2.a generación), Express5800/T110j-S (2.a generación), iStorage NS100Ti y Express5800/GT110j), donde el firmware del Baseboard Management Controller (BMC) versiones Rev1.09 y anteriores es aplicado, permite a atacantes remotos omitir una autenticación y luego obtener y modificar una información de configuración BMC, conseguir información de monitoreo o reiniciar y apagar el producto vulnerable por medio de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T03:21:43.650",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:nec:baseboard_management_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF84E0EB-8806-4A47-9936-5A5B5E4F28FC",
              "versionEndIncluding": "1.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:nec:express5800\\/gt110j:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2308ECDD-EB52-4A5F-AEC9-572C997D7B6E"
            },
            {
              "criteria": "cpe:2.3:h:nec:express5800\\/t110j:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DF8BA490-25FA-404F-B448-CAD191DF3B90"
            },
            {
              "criteria": "cpe:2.3:h:nec:express5800\\/t110j-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "778B7852-A0A4-4911-977E-AA2ECC768C4F"
            },
            {
              "criteria": "cpe:2.3:h:nec:express5800\\/t110j-s_\\(2nd-gen\\):-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E8C305B8-BB17-4E33-8106-07DA90AC15E3"
            },
            {
              "criteria": "cpe:2.3:h:nec:express5800\\/t110j_\\(2nd-gen\\):-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D2DFFFCA-7BC8-41D6-B169-E5337ABE6227"
            },
            {
              "criteria": "cpe:2.3:h:nec:istorage_ns100ti:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B0927D54-D3EA-4509-8D63-E7ECC020B4BE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}