Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.
References
Link | Resource |
---|---|
https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit-os.html | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-17T03:03:49
Updated: 2020-02-17T03:03:49
Reserved: 2020-02-17T00:00:00
Link: CVE-2020-9020
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-17T04:15:10.703
Modified: 2020-02-19T18:36:19.573
Link: CVE-2020-9020
JSON object: View
Redhat Information
No data.
CWE