PT-2021-9427 · Svakom · Svakom Siime Eye

Beau Du Jour

·

Published

2021-02-08

·

Updated

2024-07-30

·

CVE-2020-11920

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Svakom Siime Eye version 14.1.00000001.3.330.0.0.3.14
Description A command injection issue resides in the HOST/IP section of the NFS settings menu in the webserver running on the device. By injecting Bash commands via shell metacharacters, the device executes arbitrary code with root privileges, as all of the device's services are running as root.
Recommendations For Svakom Siime Eye version 14.1.00000001.3.330.0.0.3.14, consider disabling the webserver or restricting access to the NFS settings menu as a temporary workaround until a patch is available. Avoid using the HOST/IP section of the NFS settings menu until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-11920

Affected Products

Svakom Siime Eye