CVE-2020-11950

HIGHCVSS 8.8/10EPSS 2.69%

Last modified

CVE-2020-11950 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.. EPSS estimates a 2.69% chance of exploitation in the next 30 days.

Description

VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.69%

83.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
VivotekCc9381-Hv Firmware<= 0222g
VivotekFd9360-H Firmware<= 0222g
VivotekFd9368-Htv Firmware<= 0222g
VivotekFd9380-H Firmware<= 0222g
VivotekFd9388-Htv Firmware<= 0222g
VivotekIb9360-H Firmware<= 0222g
VivotekIb9368-Ht Firmware<= 0222g
VivotekIb9380-H Firmware<= 0222g
VivotekIb9388-Ht Firmware<= 0222g
VivotekIt9360-H Firmware<= 0222g
VivotekIt9380-H Firmware<= 0222g
VivotekIt9388-Ht Firmware<= 0222g
VivotekMd9560-Dh Firmware<= 0222g
VivotekMd9560-H Firmware<= 0222g
VivotekFd9366-Hv Firmware<= 0222g
VivotekFd9166-Hn Firmware<= 0222g
VivotekFe9380-Hv Firmware<= 0222g
VivotekCc8160 Firmware<= 0222g
VivotekCc8160\(Hs\) Firmware<= 0222g
VivotekCc8370-Hv Firmware<= 0222g
VivotekCc8371-Hv Firmware<= 0222g
VivotekCd8371-Hntv Firmware<= 0222g
VivotekCd8371-Hnvf2 Firmware<= 0222g
VivotekFd8166a Firmware<= 0222g
VivotekFd8166a-N Firmware<= 0222g
VivotekFd8167a Firmware<= 0222g
VivotekFd8167a-S Firmware<= 0222g
VivotekFd8169a Firmware<= 0222g
VivotekFd8169a-S Firmware<= 0222g
VivotekFd8367a-V Firmware<= 0222g
VivotekFd8369a-V Firmware<= 0222g
VivotekFd816ba-Hf2 Firmware<= 0222g
VivotekFd836ba-Hvf2 Firmware<= 0222g
VivotekFd836ba-Htv Firmware<= 0222g
VivotekFd836ba-Ehvf2 Firmware<= 0222g
VivotekFd816ba-Ht Firmware<= 0222g
VivotekFd836ba-Ehtv Firmware<= 0222g
VivotekIb836ba-Ehf3 Firmware<= 0222g
VivotekIb836ba-Eht Firmware<= 0222g
VivotekIb836ba-Hf3 Firmware<= 0222g
VivotekIb836ba-Ht Firmware<= 0222g
VivotekFd816b-Hf2 Firmware<= 0222g
VivotekFd816b-Ht Firmware<= 0222g
VivotekFd836b-Ehtv Firmware<= 0222g
VivotekFd836b-Ehvf2 Firmware<= 0222g
VivotekFd836b-Htv Firmware<= 0222g
VivotekFd836b-Hvf2 Firmware<= 0222g
VivotekIb836b-Ehf3 Firmware<= 0222g
VivotekIb836b-Eht Firmware<= 0222g
VivotekIb836b-Hf3 Firmware<= 0222g

Showing 50 of 200 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-11950?
VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.
How severe is CVE-2020-11950?
CVE-2020-11950 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 2.69% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11950?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-11950?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST