9

CVE-2020-23160

Exploit
Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PyresTermod4 Firmware Version < 10.04k
   PyresTermod4 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.93% 0.933
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/Outpost24/Pyrescom-Termod-PoC
Third Party Advisory
Exploit
https://outpost24.com/blog/multiple-vulnerabilities-discovered-in-Pyrescom-Termod4-smart-device
Third Party Advisory
Exploit
Technical Description
https://pyres.com/en/solutions/termod-4/
Vendor Advisory
Product