Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-17T03:03:49
Updated: 2024-08-04T10:19:19.630Z
Reserved: 2020-02-17T00:00:00
Link: CVE-2020-9020
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-02-17T04:15:10.703
Modified: 2020-02-19T18:36:19.573
Link: CVE-2020-9020
Redhat
No data.