CVE-2020-22002
Estado: ModificadaAlta (7.5)—
An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.35%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (6)
CWE
- CWE-918
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-22002",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-04-29T15:15:10.537",
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/172839",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5545.php",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/172839",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5545.php",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de Server-Side Request Forgery (SSRF) no autenticado en Inim Electronics Smartliving SmartLAN /G/SI versiones anteriores a incluyéndola 6.x dentro de la funcionalidad GetImage. La aplicación analiza los datos proporcionados por el usuario en el parámetro GET \"host\" para construir una petición de imagen al servicio por medio del archivo onvif.cgi. Dado que no se lleva a cabo ninguna comprobación en el parámetro, un atacante puede especificar un dominio externo y obligar a la aplicación a realizar una petición HTTP a un host de destino arbitrario"
}
],
"lastModified": "2026-06-17T03:04:02.590",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:inim:smartliving_505_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D350C754-F555-46A0-BB06-383C3C201E30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:inim:smartliving_505:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "30FE3762-2144-4DF6-89C1-2181E15ACCF4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:inim:smartliving_515_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F96A2F0-E829-416E-9D19-C2820F16A954"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:inim:smartliving_515:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1EBA5461-77FB-46E5-BFDC-F470A9A97492"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:inim:smartliving_1050_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "467D8264-AD90-4AFE-BB6E-D1D62279E481"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:inim:smartliving_1050:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1BB1029D-DC9C-444A-BCE3-AF1BE074A068"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:inim:smartliving_1050g3_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BB20EF9-386F-4C5E-A4F7-B6E03E71E809"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:inim:smartliving_1050g3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0BF688BA-60F1-4F19-8CFA-6C1EFB4D4128"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:inim:smartliving_10100l_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12BD7C5C-3A1F-4900-B516-F72FD46F5B18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:inim:smartliving_10100l:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5537E090-43C2-42B1-A793-23E765A82D6E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:inim:smartliving_10100lg3_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57A3F264-9B28-4B14-AC5A-A7DA010CA991"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:inim:smartliving_10100lg3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "108A7416-7196-49E8-9181-CE27C9F1ED11"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}