CVE-2020-8964
Summary
| CVE | CVE-2020-8964 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-13 03:15:00 UTC |
| Updated | 2020-02-25 18:01:00 UTC |
| Description | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie." |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Timetoolsltd | Sc7105 | - | All | All | All |
| Hardware | Timetoolsltd | Sc7105 | - | All | All | All |
| Operating System | Timetoolsltd | Sc7105 Firmware | 1.0.007 | All | All | All |
| Operating System | Timetoolsltd | Sc7105 Firmware | 1.0.007 | All | All | All |
| Hardware | Timetoolsltd | Sc9205 | - | All | All | All |
| Hardware | Timetoolsltd | Sc9205 | - | All | All | All |
| Operating System | Timetoolsltd | Sc9205 Firmware | 1.0.007 | All | All | All |
| Operating System | Timetoolsltd | Sc9205 Firmware | 1.0.007 | All | All | All |
| Hardware | Timetoolsltd | Sc9705 | - | All | All | All |
| Hardware | Timetoolsltd | Sc9705 | - | All | All | All |
| Operating System | Timetoolsltd | Sc9705 Firmware | 1.0.007 | All | All | All |
| Operating System | Timetoolsltd | Sc9705 Firmware | 1.0.007 | All | All | All |
| Hardware | Timetoolsltd | Sr7110 | - | All | All | All |
| Hardware | Timetoolsltd | Sr7110 | - | All | All | All |
| Operating System | Timetoolsltd | Sr7110 Firmware | 1.0.007 | All | All | All |
| Operating System | Timetoolsltd | Sr7110 Firmware | 1.0.007 | All | All | All |
| Hardware | Timetoolsltd | Sr9210 | - | All | All | All |
| Hardware | Timetoolsltd | Sr9210 | - | All | All | All |
| Operating System | Timetoolsltd | Sr9210 Firmware | 1.0.007 | All | All | All |
| Operating System | Timetoolsltd | Sr9210 Firmware | 1.0.007 | All | All | All |
| Hardware | Timetoolsltd | Sr9750 | - | All | All | All |
| Hardware | Timetoolsltd | Sr9750 | - | All | All | All |
| Operating System | Timetoolsltd | Sr9750 Firmware | 1.0.007 | All | All | All |
| Operating System | Timetoolsltd | Sr9750 Firmware | 1.0.007 | All | All | All |
| Hardware | Timetoolsltd | Sr9850 | - | All | All | All |
| Hardware | Timetoolsltd | Sr9850 | - | All | All | All |
| Operating System | Timetoolsltd | Sr9850 Firmware | 1.0.007 | All | All | All |
| Operating System | Timetoolsltd | Sr9850 Firmware | 1.0.007 | All | All | All |
| Hardware | Timetoolsltd | T100 | - | All | All | All |
| Hardware | Timetoolsltd | T100 | - | All | All | All |
| Operating System | Timetoolsltd | T100 Firmware | 1.0.003 | All | All | All |
| Operating System | Timetoolsltd | T100 Firmware | 1.0.003 | All | All | All |
| Hardware | Timetoolsltd | T300 | - | All | All | All |
| Hardware | Timetoolsltd | T300 | - | All | All | All |
| Operating System | Timetoolsltd | T300 Firmware | 1.0.003 | All | All | All |
| Operating System | Timetoolsltd | T300 Firmware | 1.0.003 | All | All | All |
| Hardware | Timetoolsltd | T550 | - | All | All | All |
| Hardware | Timetoolsltd | T550 | - | All | All | All |
| Operating System | Timetoolsltd | T550 Firmware | 1.0.003 | All | All | All |
| Operating System | Timetoolsltd | T550 Firmware | 1.0.003 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Blogger | MISC | sku11army.blogspot.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.