CVE-2020-8009

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/01/2020
Last modified:
06/02/2020

Description

AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:motu:avb_firmware:*:*:*:*:*:*:*:* 2020-01-22 (including)
cpe:2.3:h:motu:112d:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:1248:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:16a:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:24ai:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:24ao:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:624:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:828es:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:828x:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:8a:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:8d:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:8m:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:8pre-es:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:avb:-:*:*:*:*:*:*:*
cpe:2.3:h:motu:lp32:-:*:*:*:*:*:*:*