CVE-2020-10231

HIGHCVSS 7.5/10EPSS 3.68%

Last modified

CVE-2020-10231 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.. EPSS estimates a 3.68% chance of exploitation in the next 30 days.

Description

TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
3.68%

88.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
Tp-LinkNc450 Firmware1.1.1160928
Tp-LinkNc450 Firmware1.1.2161013
Tp-LinkNc450 Firmware1.1.6161124
Tp-LinkNc450 Firmware1.5.0181022
Tp-LinkNc260 Firmware1.0.5160804
Tp-LinkNc260 Firmware1.0.6161114
Tp-LinkNc260 Firmware1.5.1190805
Tp-LinkNc250 Firmware1.3.0171205
Tp-LinkNc230 Firmware1.3.0171205
Tp-LinkNc220 Firmware1.1.12160321 A
Tp-LinkNc220 Firmware1.1.14161219
Tp-LinkNc220 Firmware1.2.0170516
Tp-LinkNc220 Firmware1.3.0180105
Tp-LinkNc210 Firmware1.0.9171214
Tp-LinkNc200 Firmware2.1.6160108 A
Tp-LinkNc200 Firmware2.1.7160315 A
Tp-LinkNc200 Firmware2.1.8171109

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-10231?
TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.
How severe is CVE-2020-10231?
CVE-2020-10231 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 3.68% probability of exploitation in the next 30 days.
How do I fix CVE-2020-10231?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-10231?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST