10

CVE-2020-8964

Exploit
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Timetoolsltd ≫ Sr9850 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr9850 Version -
Timetoolsltd ≫ Sr9750 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr9750 Version -
Timetoolsltd ≫ Sc9705 Firmware Version 1.0.007
   Timetoolsltd ≫ Sc9705 Version -
Timetoolsltd ≫ Sr9210 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr9210 Version -
Timetoolsltd ≫ Sc9205 Firmware Version 1.0.007
   Timetoolsltd ≫ Sc9205 Version -
Timetoolsltd ≫ Sr7110 Firmware Version 1.0.007
   Timetoolsltd ≫ Sr7110 Version -
Timetoolsltd ≫ Sc7105 Firmware Version 1.0.007
   Timetoolsltd ≫ Sc7105 Version -
Timetoolsltd ≫ T100 Firmware Version 1.0.003
   Timetoolsltd ≫ T100 Version -
Timetoolsltd ≫ T300 Firmware Version 1.0.003
   Timetoolsltd ≫ T300 Version -
Timetoolsltd ≫ T550 Firmware Version 1.0.003
   Timetoolsltd ≫ T550 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.66% 0.882
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.html
Vendor Advisory
Exploit