DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-25189 | DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system. |
Fixes
Solution
Update to ver. 20191216 in TAT-76 series Update to ver. 20200213 in TAT-77 series
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T17:14:12.393Z
Reserved: 2019-12-20T00:00:00
Link: CVE-2020-3924
No data.
Status : Modified
Published: 2020-02-27T04:15:10.670
Modified: 2024-11-21T05:31:58.103
Link: CVE-2020-3924
No data.
OpenCVE Enrichment
No data.
EUVD