Record summary

CVE-2020-12447 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHOnkyo TX-NR585 Web Interface - Directory TraversalCVSS 7.5

Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal and local file inclusion.

Impact

An attacker can access sensitive files on the system, potentially leading to unauthorized access, information disclosure, or further exploitation.

Remediation

Apply the latest firmware update provided by the vendor to fix the directory traversal vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2020onkyolfitraversalvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:onkyo:tx-nr585_firmware:1000-0000-000-0008-0000:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2