Vulnerability Description
Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Safescan | Ta-8010 Firmware | < 7.0.3.100-ta8000-14 |
| Safescan | Ta-8010 | - |
| Safescan | Ta-8015 Firmware | < 7.0.3.100-ta8000-14 |
| Safescan | Ta-8015 | - |
| Safescan | Ta-8020 Firmware | < 7.0.3.100-ta8000-14 |
| Safescan | Ta-8020 | - |
| Safescan | Ta-8025 Firmware | < 7.0.3.100-ta8000-14 |
| Safescan | Ta-8025 | - |
| Safescan | Ta-8030 Firmware | < 7.0.3.100-ta8000-14 |
| Safescan | Ta-8030 | - |
| Safescan | Ta-8035 Firmware | < 7.0.3.100-ta8000-14 |
| Safescan | Ta-8035 | - |
| Safescan | Tm-616 Firmware | - |
| Safescan | Tm-616 | - |
Related Weaknesses (CWE)
References
- https://github.com/ProCheckUp/SafeScanExploitThird Party Advisory
- https://procheckup.com/blogs/posts/2020/february/remote-code-execution-on-biometExploitThird Party Advisory
- https://safescan.com/Product
- https://support.timemoto.com/en/s/safescan-time-clock-systems/a/firmware-update-Vendor Advisory
- https://github.com/ProCheckUp/SafeScanExploitThird Party Advisory
- https://procheckup.com/blogs/posts/2020/february/remote-code-execution-on-biometExploitThird Party Advisory
- https://safescan.com/Product
- https://support.timemoto.com/en/s/safescan-time-clock-systems/a/firmware-update-Vendor Advisory
FAQ
What is CVE-2019-12182?
CVE-2019-12182 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
How severe is CVE-2019-12182?
CVE-2019-12182 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12182?
Check the references section above for vendor advisories and patch information. Affected products include: Safescan Ta-8010 Firmware, Safescan Ta-8010, Safescan Ta-8015 Firmware, Safescan Ta-8015, Safescan Ta-8020 Firmware.