CVE-2020-8963

CRITICALCVSS 9.8/10EPSS 2.68%

Last modified

CVE-2020-8963 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.. EPSS estimates a 2.68% chance of exploitation in the next 30 days.

Description

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.68%

83.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TimetoolsltdSr9850 Firmware1.0.007
TimetoolsltdSr9750 Firmware1.0.007
TimetoolsltdSc9705 Firmware1.0.007
TimetoolsltdSr9210 Firmware1.0.007
TimetoolsltdSc9205 Firmware1.0.007
TimetoolsltdSr7110 Firmware1.0.007
TimetoolsltdSc7105 Firmware1.0.007
TimetoolsltdT100 Firmware1.0.003
TimetoolsltdT300 Firmware1.0.003
TimetoolsltdT550 Firmware1.0.003

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8963?
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.
How severe is CVE-2020-8963?
CVE-2020-8963 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.68% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8963?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8963?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST