{"api_version":"1","generated_at":"2026-07-23T11:12:09+00:00","cve":"CVE-2020-8975","urls":{"html":"https://cve.report/CVE-2020-8975","api":"https://cve.report/api/cve/CVE-2020-8975.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-8975","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-8975"},"summary":{"title":"CVE-2020-8975","description":"ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access sensitive information about the system.","state":"PUBLIC","assigner":"cve-coordination@incibe.es","published_at":"2022-10-17 22:15:00","updated_at":"2022-10-20 14:52:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://www.incibe-cert.es/en/early-warning/ics-advisories/multiple-vulnerabilities-zgr-tps200-ng","name":"https://www.incibe-cert.es/en/early-warning/ics-advisories/multiple-vulnerabilities-zgr-tps200-ng","refsource":"CONFIRM","tags":[],"title":"Multiple vulnerabilities in ZGR TPS200 NG | INCIBE-CERT","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-8975","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8975","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Discovered by the Industrial Cybersecurity team of S21sec, special mention to Aaron Flecha Menendez.","lang":""}],"nvd_cpes":[{"cve_year":"2020","cve_id":"8975","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"zigor","cpe5":"zgr_tps200_ng","cpe6":"1.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"8975","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"zigor","cpe5":"zgr_tps200_ng_firmware","cpe6":"2.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve-coordination@incibe.es","DATE_PUBLIC":"2022-09-30T11:00:00.000Z","ID":"CVE-2020-8975","STATE":"PUBLIC","TITLE":"ZGR TPS200 NG Information Exposure"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"ZGR TPS200 NG","version":{"version_data":[{"version_affected":"=","version_name":"2.00","version_value":"firmware version 2.00"},{"version_affected":"=","version_name":"1.01","version_value":"hardware version 1.01"}]}}]},"vendor_name":"ZGR"}]}},"credit":[{"lang":"eng","value":"Discovered by the Industrial Cybersecurity team of S21sec, special mention to Aaron Flecha Menendez."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access sensitive information about the system."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-201: Insertion of Sensitive Information Into Sent Data"}]}]},"references":{"reference_data":[{"name":"https://www.incibe-cert.es/en/early-warning/ics-advisories/multiple-vulnerabilities-zgr-tps200-ng","refsource":"CONFIRM","url":"https://www.incibe-cert.es/en/early-warning/ics-advisories/multiple-vulnerabilities-zgr-tps200-ng"}]},"solution":[{"lang":"eng","value":"The ZGR team is working on a new design of the TPS, which will include the necessary cybersecurity measures to address the identified vulnerabilities. Affected equipment must be connected to properly isolated and secured networks to avoid potential risks."}],"source":{"advisory":"INCIBE-2022-0936","defect":["INCIBE-2020-0029"],"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-10-17 22:15:00","lastModifiedDate":"2022-10-20 14:52:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:zigor:zgr_tps200_ng_firmware:2.00:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:zigor:zgr_tps200_ng:1.01:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"8975","Ordinal":"169330","Title":"CVE-2020-8975","CVE":"CVE-2020-8975","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"8975","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}