Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28100 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges. |
| Link | Providers |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-20-021-01 |
|
No history.
Subscriptions
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T09:18:02.477Z
Reserved: 2020-01-14T00:00:00.000Z
Link: CVE-2020-6960
No data.
Status : Modified
Published: 2020-01-22T15:15:11.617
Modified: 2026-06-17T03:24:01.233
Link: CVE-2020-6960
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD