Vulnerability Description
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combined with CVE-2020-10794 for remote root access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gira | Tks-Ip-Gateway Firmware | 4.0.7.7 |
| Gira | Tks-Ip-Gateway | - |
Related Weaknesses (CWE)
References
- https://research.hisolutions.com/2020/04/open-the-gates-insecurity-of-cloudless-ExploitThird Party Advisory
- https://research.hisolutions.com/2020/04/open-the-gates-insecurity-of-cloudless-ExploitThird Party Advisory
FAQ
What is CVE-2020-10795?
CVE-2020-10795 is a vulnerability with a CVSS score of 7.2 (HIGH). Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combined with CVE-2020-10794 for remote root access.
How severe is CVE-2020-10795?
CVE-2020-10795 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10795?
Check the references section above for vendor advisories and patch information. Affected products include: Gira Tks-Ip-Gateway Firmware, Gira Tks-Ip-Gateway.