CVE-2020-15809

spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.
References
Link Resource
https://support.spinetix.com/wiki/SpinetiX-SA-20:01 Release Notes Vendor Advisory
https://support.spinetix.com/wiki/DSOS_release_notes Release Notes Vendor Advisory
Configurations

Configuration 1

cpe:2.3:o:spinetix:dsos:*:*:*:*:*:*:*:*

Information

Published : 2021-03-24 05:15

Updated : 2021-03-26 09:17


NVD link : CVE-2020-15809

Mitre link : CVE-2020-15809

Products Affected
No products.
CWE
CWE-22

CWE-918

Server-Side Request Forgery (SSRF)