10

CVE-2020-8963

Exploit
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Timetoolsltd ≫ Sr9850 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr9850 Version -
Timetoolsltd ≫ Sr9750 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr9750 Version -
Timetoolsltd ≫ Sc9705 Firmware Version 1.0.007
   Timetoolsltd ≫ Sc9705 Version -
Timetoolsltd ≫ Sr9210 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr9210 Version -
Timetoolsltd ≫ Sc9205 Firmware Version 1.0.007
   Timetoolsltd ≫ Sc9205 Version -
Timetoolsltd ≫ Sr7110 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr7110 Version -
Timetoolsltd ≫ Sc7105 Firmware Version 1.0.007
   Timetoolsltd ≫ Sc7105 Version -
Timetoolsltd ≫ T100 Firmware Version 1.0.003
   Timetoolsltd ≫ T100 Version -
Timetoolsltd ≫ T300 Firmware Version 1.0.003
   Timetoolsltd ≫ T300 Version -
Timetoolsltd ≫ T550 Firmware Version 1.0.003
   Timetoolsltd ≫ T550 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.68% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.html
Third Party Advisory
Exploit