CVE-2020-24215
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
06/10/2020
Last modified:
20/10/2020
Description
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve arbitrary code execution.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:szuray:iptv\/h.264_video_encoder_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uaioe264-1u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uce264-1-mini:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uce264-1wb-mini:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uce264-4-1u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uce264-8-1u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhae264-16:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-16p32:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-1p2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-1p2-1u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-1s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-1w:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-1ws:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:szuray:uhce264-4p8:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



