Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7879

Опубликовано: 30 нояб. 2021
Источник: nvd
CVSS3: 8.8
CVSS3: 9.8
CVSS2: 6.8
EPSS Низкий

Описание

This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:iptime:c200_firmware:*:*:*:*:*:*:*:*
Версия до 1.0.16 (включая)
cpe:2.3:h:iptime:c200:-:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00806
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-78
CWE-78

Связанные уязвимости

github
около 4 лет назад

This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.

EPSS

Процентиль: 74%
0.00806
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-78
CWE-78