CVE-2020-3924
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
27/02/2020
Last modified:
21/07/2021
Description
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:tonnet:tat-77104g1_firmware:*:*:*:*:*:*:*:* | tat-77104g1_20190107 (including) | |
cpe:2.3:h:tonnet:tat-77104g1:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tonnet:tat-70432n_firmware:*:*:*:*:*:*:*:* | tat-77208g1_20181225 (including) | |
cpe:2.3:h:tonnet:tat-70432n:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tonnet:tat-71416g1_firmware:*:*:*:*:*:*:*:* | tat-71416g1_20181225 (including) | |
cpe:2.3:h:tonnet:tat-71416g1:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tonnet:tat-71832g1_firmware:*:*:*:*:*:*:*:* | tat-71832g1_20190510 (including) | |
cpe:2.3:h:tonnet:tat-71832g1:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tonnet:tat-76104g3_firmware:*:*:*:*:*:*:*:* | 20181220_76104g3 (including) | |
cpe:2.3:h:tonnet:tat-76104g3:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tonnet:tat-76108g3_firmware:*:*:*:*:*:*:*:* | 20181221_76208g3 (including) | |
cpe:2.3:h:tonnet:tat-76108g3:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tonnet:tat-76116g3_firmware:*:*:*:*:*:*:*:* | 20181221_76216g3 (including) | |
cpe:2.3:h:tonnet:tat-76116g3:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tonnet:tat-76132g3_firmware:*:*:*:*:*:*:*:* | tat-70832g3_20181221-1 (including) |
To consult the complete list of CPE names with products and versions, see this page