« Volver al listado

CVE-2020-29380

Estado: ModificadaMedia (5.9)—

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker can intercept passwords sent in cleartext and conduct a man-in-the-middle attack on the management of the appliance.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-29380",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-11-29T01:15:11.147",
  "references": [
    {
      "url": "https://seclists.org/fulldisclosure/2020/Jul/14",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://seclists.org/fulldisclosure/2020/Jul/14",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        },
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker can intercept passwords sent in cleartext and conduct a man-in-the-middle attack on the management of the appliance."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en los dispositivos OLT V-SOL V1600D versiones V2.03.69 y V2.03.57, V1600D4L versión V1.01.49, V1600D-MINI versión V1.01.48, V1600G1 versiones V2.0.7 y V1.9.7, y V1600G2 versión V1.1.4. TELNET es ofrecido por defecto, pero SSH no siempre está disponible. Un atacante puede interceptar contraseñas enviadas en texto plano y conducir un ataque de tipo man-in-the-middle en la administración del dispositivo"
    }
  ],
  "lastModified": "2026-06-17T03:11:14.870",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vsolcn:v1600d_firmware:2.03.57:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E209E77-9032-445E-8537-63D84ABB3E94"
            },
            {
              "criteria": "cpe:2.3:o:vsolcn:v1600d_firmware:2.03.69:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CF8489F-58DC-4A4D-B19B-D31FD65356EB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:vsolcn:v1600d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D6A406A6-DEBA-4715-9F9B-21D3FA94FCED"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vsolcn:v1600d4l_firmware:1.01.49:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6441837A-B3BA-4CB6-8507-40D089DC82BA"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:vsolcn:v1600d4l:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DF4991AB-71EA-4DF1-8142-E13985017197"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vsolcn:v1600d-mini_firmware:1.01.48:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C40945D6-0A82-4EF6-8665-E177184874DE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:vsolcn:v1600d-mini:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B8407505-E9A3-4435-A8CC-70BD24245516"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vsolcn:v1600g1_firmware:1.9.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BDA94F4-CEBF-4CC3-8799-C2C6424A7127"
            },
            {
              "criteria": "cpe:2.3:o:vsolcn:v1600g1_firmware:2.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D5E0E91-7C0C-4696-9E8C-269D872B9E2A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:vsolcn:v1600g1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "351D7DCA-129F-417A-822F-7FA2A2D6CE83"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vsolcn:v1600g2_firmware:1.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03765CFC-6994-41B0-9650-DD1EB2C5A886"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:vsolcn:v1600g2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5892BFA9-5870-4C42-AD71-7984C975ABDF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}