CVE-2020-15809: Spinetix Diva Firmware

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.

Affected products

  • Spinetix Diva Firmware: up to and including 4.5.2-1.0.36229
  • Spinetix Dsos: up to and including 4.5.2-1.0.2-1eb2ffbd
  • Spinetix HMP300 Firmware: up to and including 4.5.2-1.0.36229
  • Spinetix HMP350 Firmware: up to and including 4.5.2-1.0.36229
  • Spinetix HMP400 Firmware: up to and including 4.5.2-1.0.2-1eb2ffbd
  • Spinetix HMP400W Firmware: up to and including 4.5.2-1.0.2-1eb2ffbd

Published 2021-03-24. Last modified 2026-06-17.