CVE-2020-22159
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
Affected (3)
Products: Evertz: 3080ipx Firmware, 7801fc Firmware, 7890ixg Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version exe-guest-v1.2-r26125 |
| Running on/with | Platform Versions |
|---|---|
Evertz 3080ipx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.3 build_27 |
| Running on/with | Platform Versions |
|---|---|
Evertz 7801fc | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v494 |
| Running on/with | Platform Versions |
|---|---|
Evertz 7890ixg | All versions |
References (4)
Source: cve@mitre.org
Exploit
Source: cve@mitre.org
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Timeline
No history available yet.