CVE-2020-8964

CRITICALCVSS 9.8/10EPSS 3.66%

Last modified

CVE-2020-8964 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie.". EPSS estimates a 3.66% chance of exploitation in the next 30 days.

Description

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
3.66%

88.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TimetoolsltdSr9850 Firmware1.0.007
TimetoolsltdSr9750 Firmware1.0.007
TimetoolsltdSc9705 Firmware1.0.007
TimetoolsltdSr9210 Firmware1.0.007
TimetoolsltdSc9205 Firmware1.0.007
TimetoolsltdSr7110 Firmware1.0.007
TimetoolsltdSc7105 Firmware1.0.007
TimetoolsltdT100 Firmware1.0.003
TimetoolsltdT300 Firmware1.0.003
TimetoolsltdT550 Firmware1.0.003

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8964?
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
How severe is CVE-2020-8964?
CVE-2020-8964 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 3.66% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8964?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8964?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST