CVE-2020-22159

EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:evertz:3080ipx_firmware:exe-guest-v1.2-r26125:*:*:*:*:*:*:*
cpe:2.3:h:evertz:3080ipx:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:evertz:7801fc_firmware:1.3:build_27:*:*:*:*:*:*
cpe:2.3:h:evertz:7801fc:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:evertz:7890ixg_firmware:v494:*:*:*:*:*:*:*
cpe:2.3:h:evertz:7890ixg:-:*:*:*:*:*:*:*

History

28 Jul 2023, 13:52

Type Values Removed Values Added
References (MISC) https://sku11army.blogspot.com/2020/02/evertz-path-transversal-arbitrary-file.html - (MISC) https://sku11army.blogspot.com/2020/02/evertz-path-transversal-arbitrary-file.html - Permissions Required
References (MISC) https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multicast.html - (MISC) https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multicast.html - Exploit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:o:evertz:7801fc_firmware:1.3:build_27:*:*:*:*:*:*
cpe:2.3:h:evertz:7801fc:-:*:*:*:*:*:*:*
cpe:2.3:o:evertz:3080ipx_firmware:exe-guest-v1.2-r26125:*:*:*:*:*:*:*
cpe:2.3:o:evertz:7890ixg_firmware:v494:*:*:*:*:*:*:*
cpe:2.3:h:evertz:3080ipx:-:*:*:*:*:*:*:*
cpe:2.3:h:evertz:7890ixg:-:*:*:*:*:*:*:*
CWE CWE-434
First Time Evertz 7801fc
Evertz
Evertz 3080ipx Firmware
Evertz 7890ixg Firmware
Evertz 7801fc Firmware
Evertz 3080ipx
Evertz 7890ixg

18 Jul 2023, 18:24

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-18 18:15

Updated : 2024-02-28 20:33


NVD link : CVE-2020-22159

Mitre link : CVE-2020-22159

CVE.ORG link : CVE-2020-22159


JSON object : View

Products Affected

evertz

  • 7890ixg_firmware
  • 7801fc_firmware
  • 3080ipx
  • 7801fc
  • 3080ipx_firmware
  • 7890ixg
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type