CVE-2020-7357

CRITICALCVSS 9.9/10EPSS 33.87%

Last modified

CVE-2020-7357 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. EPSS estimates a 33.87% chance of exploitation in the next 30 days.

Description

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.

Metrics

CVSS 3.1
9.9/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
33.87%

98.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
CayintechCms-Se Firmware11.019179
CayintechCms-Se-Lxc FirmwareAll versions
CayintechCms-60 Firmware11.019025
CayintechCms-40 Firmware9.014197
CayintechCms-20 Firmware9.014197
CayintechCms7.511175
CayintechCms8.011175
CayintechCms8.212199

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-7357?
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
How severe is CVE-2020-7357?
CVE-2020-7357 has a CVSS score of 9.9/10 (CRITICAL severity). The EPSS model estimates a 33.87% probability of exploitation in the next 30 days.
How do I fix CVE-2020-7357?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-7357?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST