CVE-2020-3924

CRITICALCVSS 9.8/10EPSS 1.26%

Last modified

CVE-2020-3924 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.

Description

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.26%

65.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TonnetTat-77104g1 Firmware<= tat-77104g1_20190107
TonnetTat-70432n Firmware<= tat-77208g1_20181225
TonnetTat-71416g1 Firmware<= tat-71416g1_20181225
TonnetTat-71832g1 Firmware<= tat-71832g1_20190510
TonnetTat-76104g3 Firmware<= 20181220_76104g3
TonnetTat-76108g3 Firmware<= 20181221_76208g3
TonnetTat-76116g3 Firmware<= 20181221_76216g3
TonnetTat-76132g3 Firmware<= tat-70832g3_20181221-1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-3924?
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
How severe is CVE-2020-3924?
CVE-2020-3924 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.26% probability of exploitation in the next 30 days.
How do I fix CVE-2020-3924?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-3924?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST