PT-2020-20401 · Timetools · Timetools Sr9210+9

Published

2020-02-13

·

Updated

2020-02-25

·

CVE-2020-8964

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TimeTools SC7105 version 1.0.007 TimeTools SC9205 version 1.0.007 TimeTools SC9705 version 1.0.007 TimeTools SR7110 version 1.0.007 TimeTools SR9210 version 1.0.007 TimeTools SR9750 version 1.0.007 TimeTools SR9850 version 1.0.007 TimeTools T100 version 1.0.003 TimeTools T300 version 1.0.003 TimeTools T550 version 1.0.003
Description The issue allows remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a "t3.cgi" request. This is due to a hardcoded cookie.
Recommendations For TimeTools SC7105 version 1.0.007, consider disabling the t3.cgi request until a patch is available. For TimeTools SC9205 version 1.0.007, consider disabling the t3.cgi request until a patch is available. For TimeTools SC9705 version 1.0.007, consider disabling the t3.cgi request until a patch is available. For TimeTools SR7110 version 1.0.007, consider disabling the t3.cgi request until a patch is available. For TimeTools SR9210 version 1.0.007, consider disabling the t3.cgi request until a patch is available. For TimeTools SR9750 version 1.0.007, consider disabling the t3.cgi request until a patch is available. For TimeTools SR9850 version 1.0.007, consider disabling the t3.cgi request until a patch is available. For TimeTools T100 version 1.0.003, consider disabling the t3.cgi request until a patch is available. For TimeTools T300 version 1.0.003, consider disabling the t3.cgi request until a patch is available. For TimeTools T550 version 1.0.003, consider disabling the t3.cgi request until a patch is available.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8964

Affected Products

Timetools Sc7105
Timetools Sc9205
Timetools Sc9705
Timetools Sr7110
Timetools Sr9210
Timetools Sr9750
Timetools Sr9850
Timetools T100
Timetools T300
Timetools T550