Critical severity9.8NVD Advisory· Published Nov 30, 2020· Updated Jun 17, 2026
CVE-2020-29127
CVE-2020-29127
Description
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:fujitsu:eternus_storage_dx200_s4_firmware:*:*:*:*:*:*:*:*Range: <=2020-11-25
- Fujitsu/Eternus Storage DX200 S4description
- Range: <=2020-11-25
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/160255/Fujitsu-Eternus-Storage-DX200-S4-Broken-Authentication.htmlnvdExploitThird Party AdvisoryVDB Entry
- cxsecurity.com/issue/WLB-2020110215nvdExploitThird Party Advisory
- seccops.com/fujitsu-eternus-storage-dx200-s4-broken-authentication/nvdThird Party Advisory
- www.first.org/members/teams/fujitsu_psirtnvdThird Party Advisory
News mentions
0No linked articles in our index yet.