CVE-2020-8809

HIGH

Gurux GXDLMS Director <8.5.1905.1301 - RCE

Title source: llm
STIX 2.1

Description

Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and gurux.fi/updates/updates.xml. Then, the attacker can modify the contents of downloaded files. In the case of add-ins (if the user is using those), this will lead to code execution. In case of OBIS codes (which the user is always using as they are needed to communicate with the energy meters), this can lead to code execution when combined with CVE-2020-8810.

Exploits (1)

nomisec WRITEUP 1 stars
by seqred-s-a · poc
https://github.com/seqred-s-a/gxdlmsdirector-cve

Scores

CVSS v3 8.1
EPSS 0.0022
EPSS Percentile 44.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-494
Status published
Products (1)
gurux/device_language_message_specification_director < 8.5.1905.1301
Published Feb 25, 2020
Tracked Since Feb 18, 2026