EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
References
Link | Resource |
---|---|
https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multicast.html | Exploit |
https://sku11army.blogspot.com/2020/02/evertz-path-transversal-arbitrary-file.html | Permissions Required |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
No history.
Information
Published : 2023-07-18 18:15
Updated : 2023-07-28 13:52
NVD link : CVE-2020-22159
Mitre link : CVE-2020-22159
CVE.ORG link : CVE-2020-22159
JSON object : View
Products Affected
evertz
- 7890ixg_firmware
- 3080ipx
- 3080ipx_firmware
- 7801fc
- 7890ixg
- 7801fc_firmware
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type