CVE-2020-23036 describes an insecure session validation vulnerability in MEDIA NAVI Inc SMACom v1.2's wifi photo transfer module, specifically affecting the handling of the 'password' authentication parameter. This medium-severity vulnerability (CVSS 5.9) allows attackers with network access, particularly on public Wi-Fi, to intercept authentication credentials and subsequent requests via a Man-in-the-Middle attack, leading to high confidentiality impact. While the vulnerability has no known active exploits, public exploit code, or significant community discussion, its potential for credential exposure warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2CPE matchmatch criteria | cpe:2.3:a:medianavi:smacom:1.2:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.