CVE-2020-27540
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/01/2021
Last modified:
02/02/2021
Description
Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration from SD card file vc\version.json. fw-sign parameter and from this configuration is directly inserted into a bash command. Firmware update is run automatically if there is special file on the inserted SD card.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:company:cs-c2shw_firmware:5.0.082.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:company:cs-c2shw:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



