RULE(RULE ID:333410)

Rule General Information
Release Date: 2021-01-08
Rule Name: Vantage Velocity Field Unit Remote Code Execution Vulnerability (CVE-2020-9020)
Severity:
CVE ID:
Rule Protection Details
Description: Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit-os.html
Solutions
There is no information about possible countermeasures known. Recommended to follow the manufacturer's homepage for solutions:
https://www.iteris.com/