10

CVE-2020-3924

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TonnetTat-77104g1 Firmware Version <= tat-77104g1_20190107
   TonnetTat-77104g1 Version-
TonnetTat-70432n Firmware Version <= tat-77208g1_20181225
   TonnetTat-70432n Version-
TonnetTat-71416g1 Firmware Version <= tat-71416g1_20181225
   TonnetTat-71416g1 Version-
TonnetTat-71832g1 Firmware Version <= tat-71832g1_20190510
   TonnetTat-71832g1 Version-
TonnetTat-76104g3 Firmware Version <= 20181220_76104g3
   TonnetTat-76104g3 Version-
TonnetTat-76108g3 Firmware Version <= 20181221_76208g3
   TonnetTat-76108g3 Version-
TonnetTat-76116g3 Firmware Version <= 20181221_76216g3
   TonnetTat-76116g3 Version-
TonnetTat-76132g3 Firmware Version <= tat-70832g3_20181221-1
   TonnetTat-76132g3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.604
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
twcert@cert.org.tw 6.4 0.5 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.