Vulnerability Description
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Safescan | Timemoto Tm-616 Firmware | - |
| Safescan | Timemoto Tm-616 | - |
| Safescan | Ta-8035 Firmware | - |
| Safescan | Ta-8035 | - |
| Safescan | Ta-8010 Firmware | - |
| Safescan | Ta-8010 | - |
| Safescan | Ta-8015 Firmware | - |
| Safescan | Ta-8015 | - |
| Safescan | Ta-8020 Firmware | - |
| Safescan | Ta-8020 | - |
| Safescan | Ta-8025 Firmware | - |
| Safescan | Ta-8025 | - |
| Safescan | Ta-8030 Firmware | - |
| Safescan | Ta-8030 | - |
Related Weaknesses (CWE)
References
- https://github.com/ProCheckUp/SafeScanExploitThird Party Advisory
- https://procheckup.com/blogs/posts/2020/february/remote-code-execution-on-biometExploitThird Party Advisory
- https://support.timemoto.com/en/s/safescan-time-clock-systems/a/firmware-update-
- https://github.com/ProCheckUp/SafeScanExploitThird Party Advisory
- https://procheckup.com/blogs/posts/2020/february/remote-code-execution-on-biometExploitThird Party Advisory
- https://support.timemoto.com/en/s/safescan-time-clock-systems/a/firmware-update-
FAQ
What is CVE-2019-12183?
CVE-2019-12183 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.
How severe is CVE-2019-12183?
CVE-2019-12183 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12183?
Check the references section above for vendor advisories and patch information. Affected products include: Safescan Timemoto Tm-616 Firmware, Safescan Timemoto Tm-616, Safescan Ta-8035 Firmware, Safescan Ta-8035, Safescan Ta-8010 Firmware.