« Back to list

CVE-2020-8232

Status: ModifiedMedium (6.5)—

An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2020-8232",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "EdgeSwitch firmware v1.9.0 and prior",
          "versions": [
            {
              "status": "affected",
              "version": "Fixed in EdgeMax EdgeSwitch firmware v1.9.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-08-17T16:15:13.780",
  "references": [
    {
      "url": "https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695c",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://www.ui.com/download/edgemax",
      "tags": [
        "Product"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695c",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ui.com/download/edgemax",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages."
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad de divulgación de información en el firmware EdgeMax EdgeSwitch versión v1.9.0,  que permitía a unos usuarios de solo lectura poder obtener información no autorizada por medio de las páginas de una comunidad SNMP."
    }
  ],
  "lastModified": "2026-06-17T03:26:06.030",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ui:edgeswitch_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99D34145-C467-493B-8055-6CB58FE29C37",
              "versionEndExcluding": "1.9.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ui:ep-16-xg:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AED6B48F-78E6-4BE2-A89C-36887E3CE63B"
            },
            {
              "criteria": "cpe:2.3:h:ui:ep-s16:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C52B2CB9-844B-4720-BEC9-A73C9994C7AC"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-12f:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "35E11BF8-2295-4DC3-B463-DC305B2ED456"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-16-150w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AD4B5024-6E26-4011-9392-26E304C0B00C"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-24-250w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EBA2938D-8AF2-47D5-B881-AD27A999989D"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-24-500w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CDFD81A-C3D6-4B54-97C6-718FEB23C57C"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-24-lite:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0085DBEE-368A-400D-A2E7-AC090CCD6324"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-48-500w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D7AC5ECE-A2E4-4AD8-B65D-4B5CFFF0A044"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-48-750w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "287F2ABB-2855-4938-A5F3-857744ABC4E6"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-48-lite:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0C8A7623-0F2F-49F3-81F4-515E29A907EF"
            },
            {
              "criteria": "cpe:2.3:h:ui:es-8-150w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CD0CDC1D-D5F7-437D-9544-95E8DBFBF1F7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}