UBUNTU-CVE-2020-28713

Source
https://ubuntu.com/security/CVE-2020-28713
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2020-28713
Upstream
  • CVE-2020-28713
Published
2021-06-08T19:15:00Z
Modified
2026-05-20T16:04:24.787744552Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote users to send push notification events via an exposed PNS server. A remote attacker can passively record push notification events which are sent over an insecure web request. The web service does not authenticate requests, and allows attackers to send an indefinite amount of motion or doorbell events to a user's mobile application by either replaying or deliberately crafting false events.

References

Affected packages

Ubuntu:16.04:LTS
sma

Package

Name
sma
Purl
pkg:deb/ubuntu/sma?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "sma",
            "binary_version": "1.4-3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json"
Ubuntu:18.04:LTS
sma

Package

Name
sma
Purl
pkg:deb/ubuntu/sma?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4-3
1.4-3build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "sma",
            "binary_version": "1.4-3build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json"
Ubuntu:20.04:LTS
sma

Package

Name
sma
Purl
pkg:deb/ubuntu/sma?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4-3build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "sma",
            "binary_version": "1.4-3build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json"
Ubuntu:22.04:LTS
sma

Package

Name
sma
Purl
pkg:deb/ubuntu/sma?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4-3.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "sma",
            "binary_version": "1.4-3.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json"
Ubuntu:24.04:LTS
sma

Package

Name
sma
Purl
pkg:deb/ubuntu/sma?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4-3.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "sma",
            "binary_version": "1.4-3.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json"
Ubuntu:25.10
sma

Package

Name
sma
Purl
pkg:deb/ubuntu/sma?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4-3.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "sma",
            "binary_version": "1.4-3.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json"
Ubuntu:26.04:LTS
sma

Package

Name
sma
Purl
pkg:deb/ubuntu/sma?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4-3.1
1.4-3.1build1
1.4-3.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "sma",
            "binary_version": "1.4-3.2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28713.json"