PT-2023-11612 · Evertz · Evertz 3080Ipx+2

Linuxmonr4

·

Published

2023-07-18

·

Updated

2023-07-28

·

CVE-2020-22159

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EVERTZ devices 3080IPX version exe-guest-v1.2-r26125 EVERTZ devices 7801FC version 1.3 Build 27 EVERTZ devices 7890IXG version V494
Description The issue allows an authenticated attacker to perform Arbitrary File Upload, enabling them to upload a webshell or overwrite critical system files.
Recommendations For EVERTZ devices 3080IPX version exe-guest-v1.2-r26125, consider restricting access to the file upload functionality until a patch is available. For EVERTZ devices 7801FC version 1.3 Build 27, restrict access to critical system files to minimize the risk of exploitation. For EVERTZ devices 7890IXG version V494, avoid using the vulnerable file upload feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-22159

Affected Products

Evertz 3080Ipx
Evertz 7801Fc
Evertz 7890Ixg