René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

117 lines
3.5 KiB
JSON

{
"id": "CVE-2020-7243",
"sourceIdentifier": "cve@mitre.org",
"published": "2020-01-20T22:15:11.063",
"lastModified": "2020-01-24T22:33:06.163",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharacters in the URL field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)"
},
{
"lang": "es",
"value": "Los dispositivos Comtech Stampede FX-1010 versi\u00f3n 7.4.3, permiten a administradores autenticados remotos lograr una ejecuci\u00f3n de c\u00f3digo remota al navegar a la p\u00e1gina Fetch URL e ingresar metacaracteres de shell en el campo URL. (En algunos casos, la autenticaci\u00f3n puede ser lograda con la contrase\u00f1a comtech para la cuenta comtech)."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:comtechtel:stampede_fx-1010_firmware:7.4.3:*:*:*:*:*:*:*",
"matchCriteriaId": "E40F6E42-2191-4686-9631-81E8D134809F"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:comtechtel:stampede_fx-1010:-:*:*:*:*:*:*:*",
"matchCriteriaId": "41DFD1AA-89A6-4C33-A686-8A95EE45EDF9"
}
]
}
]
}
],
"references": [
{
"url": "https://sku11army.blogspot.com/2020/01/comtech-multiple-authenticated-rce-on.html",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}