CVE-2020-22159

E

VERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:evertz:3080ipx_firmware:exe-guest-v1.2-r26125:*:*:*:*:*:*:*
cpe:2.3:h:evertz:3080ipx:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:evertz:7801fc_firmware:1.3:build_27:*:*:*:*:*:*
cpe:2.3:h:evertz:7801fc:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:evertz:7890ixg_firmware:v494:*:*:*:*:*:*:*
cpe:2.3:h:evertz:7890ixg:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:13

Type Values Removed Values Added
References () https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multicast.html - Exploit () https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multicast.html - Exploit
References () https://sku11army.blogspot.com/2020/02/evertz-path-transversal-arbitrary-file.html - Permissions Required () https://sku11army.blogspot.com/2020/02/evertz-path-transversal-arbitrary-file.html - Permissions Required

Information

Published : 2023-07-18 18:15

Updated : 2024-11-21 05:13


NVD link : CVE-2020-22159

Mitre link : CVE-2020-22159

CVE.ORG link : CVE-2020-22159


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type