CVE-2020-27220 describes a critical authorization bypass vulnerability in the Eclipse Hono AMQP and MQTT protocol adapters. An authenticated gateway device, or even a non-gateway device masquerading as one, could receive command and control messages intended for other devices within the same tenant without proper authorization checks. This flaw carries a high CVSS score of 8.8, indicating a network-based attack with low complexity, requiring only low privileges, and potentially leading to high impact on confidentiality, integrity, and availability. While the EPSS score is low, suggesting a low probability of exploitation, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.0, <= 1.4.4CPE matchmatch criteria | cpe:2.3:a:eclipse:hono:*:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:eclipse:hono:1.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.