9.9

CVE-2020-7357

Exploit

Cayin CMS Command Injection

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cayintech ≫ Cms-se Firmware Version 11.0 Update 19179
   Cayintech ≫ Cms-se Version -
Cayintech ≫ Cms-se Firmware Version 11.0 Update 19025
   Cayintech ≫ Cms-se Version -
Cayintech ≫ Cms-se Firmware Version 11.0 Update 18325
   Cayintech ≫ Cms-se Version -
Cayintech ≫ Cms-se-lxc Firmware Version -
   Cayintech ≫ Cms-se-lxc Version -
Cayintech ≫ Cms-60 Firmware Version 11.0 Update 19025
   Cayintech ≫ Cms-60 Version -
Cayintech ≫ Cms-40 Firmware Version 9.0 Update 14197
   Cayintech ≫ Cms-40 Version -
Cayintech ≫ Cms-40 Firmware Version 9.0 Update 14199
   Cayintech ≫ Cms-40 Version -
Cayintech ≫ Cms-40 Firmware Version 9.0 Update 14093
   Cayintech ≫ Cms-40 Version -
Cayintech ≫ Cms-20 Firmware Version 9.0 Update 14197
   Cayintech ≫ Cms-20 Version -
Cayintech ≫ Cms-20 Firmware Version 9.0 Update 14092
   Cayintech ≫ Cms-20 Version -
Cayintech ≫ Cms Version 7.5 Update 11175
Cayintech ≫ Cms Version 8.0 Update 11175
Cayintech ≫ Cms Version 8.2 Update 12199
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 32.09% 0.981
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Rapid7 9.6 3.1 5.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://github.com/rapid7/metasploit-framework/pull/13607
Patch
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/182925
Third Party Advisory
VDB Entry
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5570.php
Third Party Advisory
Exploit