Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8974

Опубликовано: 17 окт. 2022
Источник: nvd
CVSS3: 10
CVSS3: 9.1
EPSS Низкий

Описание

In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modifications, rendering the device unusable.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zigor:zgr_tps200_ng_firmware:2.00:*:*:*:*:*:*:*
cpe:2.3:h:zigor:zgr_tps200_ng:1.01:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00317
Низкий

10 Critical

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modifications, rendering the device unusable.

EPSS

Процентиль: 54%
0.00317
Низкий

10 Critical

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-434
CWE-434