JUNG Smart Visu Server KNX Group Address backdoor
CVE-2017-20084

5.3MEDIUM

Key Information:

Vendor

Jung

Vendor
CVE Published:
22 June 2022

What is CVE-2017-20084?

A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. Affected by this vulnerability is an unknown functionality of the component KNX Group Address. The manipulation leads to backdoor. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.

Affected Version(s)

Smart Visu Server 1.0.804

Smart Visu Server 1.0.830

Smart Visu Server 1.0.832

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

T. Weber
.