|
|||
Rule General Information |
---|
Release Date: | 2021-01-08 | |
Rule Name: | Vantage Velocity Field Unit Remote Code Execution Vulnerability (CVE-2020-9020) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field. | |
Impact: | An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Others | |
Reference: | https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit-os.html |
|
Solutions |
---|
There is no information about possible countermeasures known. Recommended to follow the manufacturer's homepage for solutions: https://www.iteris.com/ |