CVE-2020-11949

MEDIUMCVSS 6.5/10EPSS 1.19%

Last modified

CVE-2020-11949 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.. EPSS estimates a 1.19% chance of exploitation in the next 30 days.

Description

testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.19%

64.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
VivotekCc9381-Hv Firmware<= 0222g
VivotekFd9360-H Firmware<= 0222g
VivotekFd9368-Htv Firmware<= 0222g
VivotekFd9380-H Firmware<= 0222g
VivotekFd9388-Htv Firmware<= 0222g
VivotekIb9360-H Firmware<= 0222g
VivotekIb9368-Ht Firmware<= 0222g
VivotekIb9380-H Firmware<= 0222g
VivotekIb9388-Ht Firmware<= 0222g
VivotekIt9360-H Firmware<= 0222g
VivotekIt9380-H Firmware<= 0222g
VivotekIt9388-Ht Firmware<= 0222g
VivotekMd9560-Dh Firmware<= 0222g
VivotekMd9560-H Firmware<= 0222g
VivotekFd9366-Hv Firmware<= 0222g
VivotekFd9166-Hn Firmware<= 0222g
VivotekFe9380-Hv Firmware<= 0222k
VivotekCc8160 Firmware<= 0113b
VivotekCc8160\(Hs\) Firmware<= 0113b
VivotekCc8370-Hv Firmware<= 0213b
VivotekCc8371-Hv Firmware<= 0113b
VivotekCd8371-Hntv Firmware<= 0113b
VivotekCd8371-Hnvf2 Firmware<= 0113b
VivotekFd8166a Firmware<= 0213b
VivotekFd8166a-N Firmware<= 0113b
VivotekFd8167a Firmware<= 0213b
VivotekFd8169a Firmware<= 0213b
VivotekFd8367a-V Firmware<= 0213b
VivotekFd8369a-V Firmware<= 0213b
VivotekFd816ba-Hf2 Firmware<= 0113b
VivotekFd836ba-Hvf2 Firmware<= 0113b
VivotekFd836ba-Htv Firmware<= 0113b
VivotekFd836ba-Ehvf2 Firmware<= 0113b
VivotekFd816ba-Ht Firmware<= 0113b
VivotekFd836ba-Ehtv Firmware<= 0113b
VivotekIb836ba-Ehf3 Firmware<= 0113b
VivotekIb836ba-Eht Firmware<= 0113b
VivotekIb836ba-Hf3 Firmware<= 0113b
VivotekIb836ba-Ht Firmware<= 0113b
VivotekFd816b-Hf2 Firmware<= 0113b
VivotekFd816b-Ht Firmware<= 0113b
VivotekFd836b-Ehtv Firmware<= 0113b
VivotekFd836b-Ehvf2 Firmware<= 0113b
VivotekFd836b-Htv Firmware<= 0113b
VivotekFd836b-Hvf2 Firmware<= 0113b
VivotekIb836b-Ehf3 Firmware<= 0113b
VivotekIb836b-Eht Firmware<= 0113b
VivotekIb836b-Hf3 Firmware<= 0113b
VivotekIb836b-Hrf3 Firmware<= 0113b
VivotekIb836b-Ht Firmware<= 0113b

Showing 50 of 194 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-11949?
testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.
How severe is CVE-2020-11949?
CVE-2020-11949 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.19% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11949?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-11949?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST