CVE-2020-23160

Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.
References
Link Resource
https://github.com/Outpost24/Pyrescom-Termod-PoC Exploit Third Party Advisory
https://outpost24.com/blog/multiple-vulnerabilities-discovered-in-Pyrescom-Termod4-smart-device Exploit Technical Description Third Party Advisory
https://pyres.com/en/solutions/termod-4/ Product Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:pyres:termod4:-:*:*:*:*:*:*:*
cpe:2.3:o:pyres:termod4_firmware:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-01-26 18:15

Updated : 2021-03-17 12:53


NVD link : CVE-2020-23160

Mitre link : CVE-2020-23160

CVE.ORG link : CVE-2020-23160


JSON object : View

Products Affected

pyres

  • termod4_firmware
  • termod4