CVE-2020-3924

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
27/02/2020
Last modified:
21/07/2021

Description

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tonnet:tat-77104g1_firmware:*:*:*:*:*:*:*:* tat-77104g1_20190107 (including)
cpe:2.3:h:tonnet:tat-77104g1:-:*:*:*:*:*:*:*
cpe:2.3:o:tonnet:tat-70432n_firmware:*:*:*:*:*:*:*:* tat-77208g1_20181225 (including)
cpe:2.3:h:tonnet:tat-70432n:-:*:*:*:*:*:*:*
cpe:2.3:o:tonnet:tat-71416g1_firmware:*:*:*:*:*:*:*:* tat-71416g1_20181225 (including)
cpe:2.3:h:tonnet:tat-71416g1:-:*:*:*:*:*:*:*
cpe:2.3:o:tonnet:tat-71832g1_firmware:*:*:*:*:*:*:*:* tat-71832g1_20190510 (including)
cpe:2.3:h:tonnet:tat-71832g1:-:*:*:*:*:*:*:*
cpe:2.3:o:tonnet:tat-76104g3_firmware:*:*:*:*:*:*:*:* 20181220_76104g3 (including)
cpe:2.3:h:tonnet:tat-76104g3:-:*:*:*:*:*:*:*
cpe:2.3:o:tonnet:tat-76108g3_firmware:*:*:*:*:*:*:*:* 20181221_76208g3 (including)
cpe:2.3:h:tonnet:tat-76108g3:-:*:*:*:*:*:*:*
cpe:2.3:o:tonnet:tat-76116g3_firmware:*:*:*:*:*:*:*:* 20181221_76216g3 (including)
cpe:2.3:h:tonnet:tat-76116g3:-:*:*:*:*:*:*:*
cpe:2.3:o:tonnet:tat-76132g3_firmware:*:*:*:*:*:*:*:* tat-70832g3_20181221-1 (including)