CVE-2020-25195

The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-345-02 Third Party Advisory US Government Resource
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:6:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:7:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hosteng:h0-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h0-ecom100:9:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hosteng:h2-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h2-ecom100:5:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hosteng:h2-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h2-ecom100:8:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hosteng:h4-ecom100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hosteng:h4-ecom100:-:*:*:*:*:*:*:*

Information

Published : 2020-12-15 12:15

Updated : 2020-12-18 06:59


NVD link : CVE-2020-25195

Mitre link : CVE-2020-25195


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

hosteng

  • h4-ecom100
  • h2-ecom100
  • h0-ecom100_firmware
  • h2-ecom100_firmware
  • h0-ecom100
  • h4-ecom100_firmware