« Volver al listado

CVE-2020-9020

Estado: ModificadaCrítica (9.8)—

Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-9020",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-02-17T04:15:10.703",
  "references": [
    {
      "url": "https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit-os.html",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit-os.html",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field."
    },
    {
      "lang": "es",
      "value": "Los dispositivos Iteris Vantage Velocity Field Unit versiones 2.3.1, 2.4.2 y 3.0, permite una inyección de comandos de Sistema Operativo en el archivo cgi-bin/timeconfig.py por medio de metacaracteres de shell en el campo NTP Server."
    }
  ],
  "lastModified": "2026-06-17T03:27:21.247",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iteris:vantage_velocity_firmware:2.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB449754-1894-447B-B934-9237E6CCE69C"
            },
            {
              "criteria": "cpe:2.3:o:iteris:vantage_velocity_firmware:2.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D95B2F97-3C94-4F34-AA32-F8BCD7D89381"
            },
            {
              "criteria": "cpe:2.3:o:iteris:vantage_velocity_firmware:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC27E567-3A99-45FF-9555-B59BE469F5BE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iteris:vantage_velocity:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E215533A-B487-4FBD-85C7-3328CFE975BD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}