« Volver al listado

CVE-2020-7357

Estado: ModificadaCrítica (9.9)—

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7357",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@rapid7.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "cve@rapid7.com",
      "affectedData": [
        {
          "vendor": "Cayin Technology",
          "product": "Cayin CMS-SE",
          "versions": [
            {
              "status": "affected",
              "version": "11.0 Build 19179",
              "versionType": "custom",
              "lessThanOrEqual": "11.0 Build 19179"
            }
          ]
        },
        {
          "vendor": "Cayin Technology",
          "product": "Cayin CMS-60",
          "versions": [
            {
              "status": "affected",
              "version": "11.0 Build 19025",
              "versionType": "custom",
              "lessThanOrEqual": "11.0 Build 19025"
            }
          ]
        },
        {
          "vendor": "Cayin Technology",
          "product": "Cayin CMS-40",
          "versions": [
            {
              "status": "affected",
              "version": "9.0 Build 14917",
              "versionType": "custom",
              "lessThanOrEqual": "9.0 Build 14917"
            }
          ]
        },
        {
          "vendor": "Cayin Technology",
          "product": "Cayin CMS-20",
          "versions": [
            {
              "status": "affected",
              "version": "9.0 Build 14917",
              "versionType": "custom",
              "lessThanOrEqual": "9.0 Build 14917"
            }
          ]
        },
        {
          "vendor": "Cayin Technology",
          "product": "Cayin CMS",
          "versions": [
            {
              "status": "affected",
              "version": "8.2 Build 12199"
            },
            {
              "status": "affected",
              "version": "8.0 Build 11175"
            },
            {
              "status": "affected",
              "version": "7.5 Build 11175"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-08-06T16:15:13.670",
  "references": [
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/182925",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@rapid7.com"
    },
    {
      "url": "https://github.com/rapid7/metasploit-framework/pull/13607",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "cve@rapid7.com"
    },
    {
      "url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5570.php",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@rapid7.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/182925",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/rapid7/metasploit-framework/pull/13607",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5570.php",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@rapid7.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5."
    },
    {
      "lang": "es",
      "value": "Cayin CMS sufre de una vulnerabilidad de inyección de comando semi-ciega autenticada del Sistema Operativo usando credenciales predeterminadas. Esta puede ser explotada para inyectar y ejecutar comandos de shell arbitrarios como usuario root por medio del parámetro POST HTTP \"NTP_Server_IP\" en la página system.cgi. Este problema afecta a varias ramas y versiones de la aplicación CMS, incluyendo a CME-SE, CMS-60, CMS-40, CMS-20 y CMS versión 8.2, 8.0 y 7.5"
    }
  ],
  "lastModified": "2026-06-17T03:24:45.693",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-se_firmware:11.0:19179:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D1B5F84-D4C4-4D13-8DCB-53749D5F80C7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cayintech:cms-se:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F24E3257-5F03-4379-BF2F-C524CF5256F7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-se_firmware:11.0:19025:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD16EE16-BD39-4EBE-AFEC-A39F86368F04"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cayintech:cms-se:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F24E3257-5F03-4379-BF2F-C524CF5256F7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-se_firmware:11.0:18325:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D2FA169-7CF6-4F78-BD29-C000D90A2609"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cayintech:cms-se:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F24E3257-5F03-4379-BF2F-C524CF5256F7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-se-lxc_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F04C6BA-40AF-4157-AFF4-4C2F8BB8336F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cayintech:cms-se-lxc:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2D9F8C07-416D-43B5-B468-50EF4B58EF50"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-60_firmware:11.0:19025:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2925EF8F-906B-4D52-A521-D4D5F527D978"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cayintech:cms-60:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A4AD4CA4-DF56-4B1C-A9DF-2E3DF7D40243"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-40_firmware:9.0:14197:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "792ED446-D39C-4DDB-B549-DC7548E530AD"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cayintech:cms-40:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "31E0FE07-200E-44B3-9D3C-A60F8C82EF17"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-40_firmware:9.0:14199:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00EC4F5B-DA7F-4B78-AB13-E827D76B11C9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cayintech:cms-40:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "31E0FE07-200E-44B3-9D3C-A60F8C82EF17"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-40_firmware:9.0:14093:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40F92801-3978-4BBD-BE65-6C25F8DD9FB1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cayintech:cms-40:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "31E0FE07-200E-44B3-9D3C-A60F8C82EF17"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-20_firmware:9.0:14197:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08A7E26E-41B2-4D4D-8DF2-95A4CABF3D0E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cayintech:cms-20:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C746A65-C574-44BD-80BE-8CBC504DB088"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms-20_firmware:9.0:14092:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E28CB1DD-9198-47A0-9A5A-8B919625BF9E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cayintech:cms-20:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C746A65-C574-44BD-80BE-8CBC504DB088"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cayintech:cms:7.5:11175:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7EA8690-173C-4185-9BE6-7706521B0EDF"
            },
            {
              "criteria": "cpe:2.3:o:cayintech:cms:8.0:11175:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B4EE6E6-F068-42D9-B479-68A77F055788"
            },
            {
              "criteria": "cpe:2.3:o:cayintech:cms:8.2:12199:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2ED7CB20-DE71-4729-9A50-BFE7504B7660"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@rapid7.com"
}