CVE-2020-7879
Summary
| CVE | CVE-2020-7879 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-30 19:15:00 UTC |
| Updated | 2021-12-01 20:13:00 UTC |
| Description | This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Iptime | C200 | - | All | All | All |
| Operating System | Iptime | C200 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| KrCERT/CC - KISA 인터넷 보호나라&KrCERT | MISC | www.boho.or.kr | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.