Vulnerability Details CVE-2018-6020
In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.0%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.4
Products affected by CVE-2018-6020
-
cpe:2.3:h:silextechnology:geh-500:-
-
cpe:2.3:h:silextechnology:geh-sd-320an:-
-
cpe:2.3:h:silextechnology:sd-320an:-
-
cpe:2.3:h:silextechnology:sx-500:-
-
cpe:2.3:o:silextechnology:geh-500_firmware:1.54
-
cpe:2.3:o:silextechnology:geh-sd-320an_firmware:geh-1.1
-
cpe:2.3:o:silextechnology:sd-320an_firmware:2.01
-
cpe:2.3:o:silextechnology:sx-500_firmware:-