CVE-2020-7357
Summary
| CVE | CVE-2020-7357 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-06 16:15:00 UTC |
| Updated | 2023-07-27 13:31:00 UTC |
| Description | Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cayintech | Cms | 7.5 | 11175 | All | All |
| Operating System | Cayintech | Cms | 8.0 | 11175 | All | All |
| Operating System | Cayintech | Cms | 8.2 | 12199 | All | All |
| Operating System | Cayintech | Cms | 7.5 | 11175 | All | All |
| Operating System | Cayintech | Cms | 8.0 | 11175 | All | All |
| Operating System | Cayintech | Cms | 8.2 | 12199 | All | All |
| Hardware | Cayintech | Cms-20 | - | All | All | All |
| Hardware | Cayintech | Cms-20 | - | All | All | All |
| Operating System | Cayintech | Cms-20 Firmware | 9.0 | 14092 | All | All |
| Operating System | Cayintech | Cms-20 Firmware | 9.0 | 14197 | All | All |
| Operating System | Cayintech | Cms-20 Firmware | 9.0 | 14092 | All | All |
| Operating System | Cayintech | Cms-20 Firmware | 9.0 | 14197 | All | All |
| Hardware | Cayintech | Cms-40 | - | All | All | All |
| Hardware | Cayintech | Cms-40 | - | All | All | All |
| Operating System | Cayintech | Cms-40 Firmware | 9.0 | 14093 | All | All |
| Operating System | Cayintech | Cms-40 Firmware | 9.0 | 14197 | All | All |
| Operating System | Cayintech | Cms-40 Firmware | 9.0 | 14199 | All | All |
| Operating System | Cayintech | Cms-40 Firmware | 9.0 | 14093 | All | All |
| Operating System | Cayintech | Cms-40 Firmware | 9.0 | 14197 | All | All |
| Operating System | Cayintech | Cms-40 Firmware | 9.0 | 14199 | All | All |
| Hardware | Cayintech | Cms-60 | - | All | All | All |
| Hardware | Cayintech | Cms-60 | - | All | All | All |
| Operating System | Cayintech | Cms-60 Firmware | 11.0 | 19025 | All | All |
| Operating System | Cayintech | Cms-60 Firmware | 11.0 | 19025 | All | All |
| Hardware | Cayintech | Cms-se | - | All | All | All |
| Hardware | Cayintech | Cms-se | - | All | All | All |
| Hardware | Cayintech | Cms-se-lxc | - | All | All | All |
| Hardware | Cayintech | Cms-se-lxc | - | All | All | All |
| Operating System | Cayintech | Cms-se-lxc Firmware | - | All | All | All |
| Operating System | Cayintech | Cms-se-lxc Firmware | - | All | All | All |
| Operating System | Cayintech | Cms-se Firmware | 11.0 | 18325 | All | All |
| Operating System | Cayintech | Cms-se Firmware | 11.0 | 19025 | All | All |
| Operating System | Cayintech | Cms-se Firmware | 11.0 | 19179 | All | All |
| Operating System | Cayintech | Cms-se Firmware | 11.0 | 18325 | All | All |
| Operating System | Cayintech | Cms-se Firmware | 11.0 | 19025 | All | All |
| Operating System | Cayintech | Cms-se Firmware | 11.0 | 19179 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cayin xPost and CMS exploits by h00die · Pull Request #13607 · rapid7/metasploit-framework · GitHub | MISC | github.com | Patch, Third Party Advisory |
| IBM X-Force Exchange | IBM | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Zero Science Lab » Cayin Content Management Server 11.0 Root Remote Command Injection | MISC | www.zeroscience.mk | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue was discovered by Gjoko Krstic of Zero Science Lab.
There are currently no legacy QID mappings associated with this CVE.