CVE-2020-8964
Last modified
CVE-2020-8964 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie.". EPSS estimates a 3.66% chance of exploitation in the next 30 days.
Description
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Timetoolsltd | Sr9850 Firmware | 1.0.007 |
| Timetoolsltd | Sr9750 Firmware | 1.0.007 |
| Timetoolsltd | Sc9705 Firmware | 1.0.007 |
| Timetoolsltd | Sr9210 Firmware | 1.0.007 |
| Timetoolsltd | Sc9205 Firmware | 1.0.007 |
| Timetoolsltd | Sr7110 Firmware | 1.0.007 |
| Timetoolsltd | Sc7105 Firmware | 1.0.007 |
| Timetoolsltd | T100 Firmware | 1.0.003 |
| Timetoolsltd | T300 Firmware | 1.0.003 |
| Timetoolsltd | T550 Firmware | 1.0.003 |
References
- https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.htmlExploit, Vendor Advisory
- https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.htmlExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8964?
How severe is CVE-2020-8964?
How do I fix CVE-2020-8964?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8958Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 …7.2
- CVE-2020-8959Western Digital WesternDigitalSSDDashboardSetup.exe before 3…7.8
- CVE-2020-8960Western Digital mycloud.com before Web Version 2.2.0-134 all…6.1
- CVE-2020-8961An issue was discovered in Avira Free-Antivirus before 15.0.…9.8
- CVE-2020-8962A stack-based buffer overflow was found on the D-Link DIR-84…9.8
- CVE-2020-8963TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR…9.8
- CVE-2020-8966There is an Improper Neutralization of Script-Related HTML T…6.1
- CVE-2020-8967There is an improper Neutralization of Special Elements used…9.8
- CVE-2020-8968Parallels Remote Application Server (RAS) allows a local att…7.1
- CVE-2020-8973ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware…8.1
- CVE-2020-8974In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware ver…9.1
- CVE-2020-8975ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware…7.5
Are you affected by CVE-2020-8964?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
