Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8976

Опубликовано: 17 окт. 2022
Источник: nvd
CVSS3: 9.6
CVSS3: 8.8
EPSS Низкий

Описание

The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious request.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zigor:zgr_tps200_ng_firmware:2.00:*:*:*:*:*:*:*
cpe:2.3:h:zigor:zgr_tps200_ng:1.01:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00158
Низкий

9.6 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious request.

EPSS

Процентиль: 37%
0.00158
Низкий

9.6 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352
CWE-352