An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29.
Un atacante no autenticado puede enviar un paquete especialmente diseñado para actualizar la sección "notes" de la página de inicio de la interfaz web. Esta vulnerabilidad afecta a los productos basados en los controladores inteligentes HID Mercury LP1501, LP1502, LP2500, LP4502 y EP4502 que contienen versiones de firmware anteriores a 1.29
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | LOW |
| Availability Impact | NONE |
AV:N/AC:L/Au:N/C:N/I:P/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | PARTIAL |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-425
|
| [email protected] | Primary |
en
CWE-425
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| hidglobal | lp1501_firmware | * | <built-in method update of dict object at 0x7c3c28831000> | Operating System |
| hidglobal | lp1502_firmware | * | <built-in method update of dict object at 0x7c3c28831b80> | Operating System |
| hidglobal | lp2500_firmware | * | <built-in method update of dict object at 0x7c3c327fd6c0> | Operating System |
| hidglobal | lp4502_firmware | * | <built-in method update of dict object at 0x7c3c476648c0> | Operating System |
| hidglobal | ep4502_firmware | * | <built-in method update of dict object at 0x7c3c28832740> | Operating System |
| carrier | lenels2_lnl-4420_firmware | * | <built-in method update of dict object at 0x7c3c28830ac0> | Operating System |
| carrier | lenels2_lnl-x2210_firmware | * | <built-in method update of dict object at 0x7c3c476bd8c0> | Operating System |
| carrier | lenels2_lnl-x2220_firmware | * | <built-in method update of dict object at 0x7c3c483ca140> | Operating System |
| carrier | lenels2_lnl-x3300_firmware | * | <built-in method update of dict object at 0x7c3c327ff640> | Operating System |
| carrier | lenels2_lnl-x4420_firmware | * | <built-in method update of dict object at 0x7c3c28833440> | Operating System |
| carrier | lenels2_s2-lp-1501_firmware | * | <built-in method update of dict object at 0x7c3c327fd440> | Operating System |
| carrier | lenels2_s2-lp-1502_firmware | * | <built-in method update of dict object at 0x7c3c685fc040> | Operating System |
| carrier | lenels2_s2-lp-2500_firmware | * | <built-in method update of dict object at 0x7c3c28832e00> | Operating System |
| carrier | lenels2_s2-lp-4502_firmware | * | <built-in method update of dict object at 0x7c3bf3b68640> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hidglobal:lp1501_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hidglobal:lp1501:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hidglobal:lp1502_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hidglobal:lp1502:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hidglobal:lp2500_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hidglobal:lp2500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hidglobal:lp4502_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hidglobal:lp4502:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hidglobal:ep4502_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hidglobal:ep4502:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_lnl-4420_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_lnl-4420:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_lnl-x2210_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_lnl-x2210:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_lnl-x2220_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_lnl-x2220:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_lnl-x3300_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_lnl-x3300:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_lnl-x4420_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_lnl-x4420:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_s2-lp-1501_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_s2-lp-1501:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_s2-lp-1502_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_s2-lp-1502:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_s2-lp-2500_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_s2-lp-2500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:carrier:lenels2_s2-lp-4502_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:carrier:lenels2_s2-lp-4502:-:*:*:*:*:*:*:* |