10
CVE-2020-3924
- EPSS 0.41%
- Veröffentlicht 27.02.2020 04:15:10
- Zuletzt bearbeitet 21.11.2024 05:31:58
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tonnet ≫ Tat-77104g1 Firmware Version <= tat-77104g1_20190107
Tonnet ≫ Tat-70432n Firmware Version <= tat-77208g1_20181225
Tonnet ≫ Tat-71416g1 Firmware Version <= tat-71416g1_20181225
Tonnet ≫ Tat-71832g1 Firmware Version <= tat-71832g1_20190510
Tonnet ≫ Tat-76104g3 Firmware Version <= 20181220_76104g3
Tonnet ≫ Tat-76108g3 Firmware Version <= 20181221_76208g3
Tonnet ≫ Tat-76116g3 Firmware Version <= 20181221_76216g3
Tonnet ≫ Tat-76132g3 Firmware Version <= tat-70832g3_20181221-1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.604 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| twcert@cert.org.tw | 6.4 | 0.5 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.