Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8105

Опубликовано: 20 дек. 2021
Источник: nvd
CVSS3: 9.6
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_t2_homekit_RF_2.0.19_s2_kvsABODE oz.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:goabode:iota_all-in-one_security_kit_firmware:*:*:*:*:*:*:*:*
Версия до 1.0.2.23_6.9v_dev_t2_homekit_rf_2.0.19_s2_kvsabode_oz (исключая)
cpe:2.3:h:goabode:iota_all-in-one_security_kit:-:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00353
Низкий

9.6 Critical

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-78
CWE-78

Связанные уязвимости

github
около 4 лет назад

OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_t2_homekit_RF_2.0.19_s2_kvsABODE oz.

EPSS

Процентиль: 57%
0.00353
Низкий

9.6 Critical

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-78
CWE-78