CVE-2020-29059

CRITICALCVSS 9.8/10EPSS 1.47%

Last modified

CVE-2020-29059 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default panger123 password for the suma123 account for certain old firmware.. EPSS estimates a 1.47% chance of exploitation in the next 30 days.

Description

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default panger123 password for the suma123 account for certain old firmware.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.47%

70.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Cdatatec72408a Firmware1.2.2
Cdatatec72408a Firmware2.4.03_000
Cdatatec72408a Firmware2.4.04_001
Cdatatec72408a Firmware2.4.05_000
Cdatatec9008a Firmware1.2.2
Cdatatec9008a Firmware2.4.03_000
Cdatatec9008a Firmware2.4.04_001
Cdatatec9008a Firmware2.4.05_000
Cdatatec9016a Firmware1.2.2
Cdatatec9016a Firmware2.4.03_000
Cdatatec9016a Firmware2.4.04_001
Cdatatec9016a Firmware2.4.05_000
Cdatatec92408a Firmware1.2.2
Cdatatec92408a Firmware2.4.03_000
Cdatatec92408a Firmware2.4.04_001
Cdatatec92408a Firmware2.4.05_000
Cdatatec92416a Firmware1.2.2
Cdatatec92416a Firmware2.4.03_000
Cdatatec92416a Firmware2.4.04_001
Cdatatec92416a Firmware2.4.05_000
Cdatatec9288 Firmware1.2.2
Cdatatec9288 Firmware2.4.03_000
Cdatatec9288 Firmware2.4.04_001
Cdatatec9288 Firmware2.4.05_000
Cdatatec97016 Firmware1.2.2
Cdatatec97016 Firmware2.4.03_000
Cdatatec97016 Firmware2.4.04_001
Cdatatec97016 Firmware2.4.05_000
Cdatatec97024p Firmware1.2.2
Cdatatec97024p Firmware2.4.03_000
Cdatatec97024p Firmware2.4.04_001
Cdatatec97024p Firmware2.4.05_000
Cdatatec97028p Firmware1.2.2
Cdatatec97028p Firmware2.4.03_000
Cdatatec97028p Firmware2.4.04_001
Cdatatec97028p Firmware2.4.05_000
Cdatatec97042p Firmware1.2.2
Cdatatec97042p Firmware2.4.03_000
Cdatatec97042p Firmware2.4.04_001
Cdatatec97042p Firmware2.4.05_000
Cdatatec97084p Firmware1.2.2
Cdatatec97084p Firmware2.4.03_000
Cdatatec97084p Firmware2.4.04_001
Cdatatec97084p Firmware2.4.05_000
Cdatatec97168p Firmware1.2.2
Cdatatec97168p Firmware2.4.03_000
Cdatatec97168p Firmware2.4.04_001
Cdatatec97168p Firmware2.4.05_000
CdatatecFd1002s Firmware1.2.2
CdatatecFd1002s Firmware2.4.03_000

Showing 50 of 112 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-29059?
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default panger123 password for the suma123 account for certain old firmware.
How severe is CVE-2020-29059?
CVE-2020-29059 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.47% probability of exploitation in the next 30 days.
How do I fix CVE-2020-29059?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-29059?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST