CVE-2020-3924
Published Feb 27, 2020
Last updated 3 years ago
Overview
- Description
- DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
- Source
- twcert@cert.org.tw
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-77
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-77104g1_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8E7B343-EFC3-4517-A6E6-15BD2A934232", "versionEndIncluding": "tat-77104g1_20190107" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-77104g1:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "241B2620-7E8D-4084-BC76-930BA8D34757" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-70432n_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB8C435E-DF83-4F09-AC8D-5EFB41D21662", "versionEndIncluding": "tat-77208g1_20181225" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-70432n:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "39B0C7D2-4719-4D4A-BAAC-00D0B4877DC7" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-71416g1_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "95377179-581F-4F72-83BC-B136BBD2C41F", "versionEndIncluding": "tat-71416g1_20181225" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-71416g1:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1DA39250-CDA5-4457-8477-0A503BCD9718" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-71832g1_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C8CFCBC-7E99-41C5-81B3-6957B2B91223", "versionEndIncluding": "tat-71832g1_20190510" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-71832g1:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CEAC4B5F-BDE4-464B-A0C6-E8805A20D33E" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-76104g3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "716D1F9D-DCE4-4683-9E0D-929706E7AD1E", "versionEndIncluding": "20181220_76104g3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-76104g3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F4E65CAD-2851-4A91-8263-43287DD9FF84" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-76108g3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86109F98-ACA7-47AF-87E9-212802BD3D4B", "versionEndIncluding": "20181221_76208g3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-76108g3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "543032E1-AC31-44FB-AE0F-583C2E34D4F6" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-76116g3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED374327-CC36-4889-A5DA-B7D23FD870B6", "versionEndIncluding": "20181221_76216g3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-76116g3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "906FA949-47AF-4C98-9469-C39892DB0B70" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tonnet:tat-76132g3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54396F2C-697A-4523-B9A2-D31C8B3CB432", "versionEndIncluding": "tat-70832g3_20181221-1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tonnet:tat-76132g3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "63417A1A-E7E7-4E6A-A09B-B539F51BCCC0" } ], "operator": "OR" } ], "operator": "AND" } ]