MEDIUM · 6.5

CVE-2020-11949

testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's ...

Vulnerability Description

testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
VivotekCc9381-Hv Firmware<= 0222g
VivotekCc9381-Hv-
VivotekFd9360-H Firmware<= 0222g
VivotekFd9360-H-
VivotekFd9368-Htv Firmware<= 0222g
VivotekFd9368-Htv-
VivotekFd9380-H Firmware<= 0222g
VivotekFd9380-H-
VivotekFd9388-Htv Firmware<= 0222g
VivotekFd9388-Htv-
VivotekIb9360-H Firmware<= 0222g
VivotekIb9360-H-
VivotekIb9368-Ht Firmware<= 0222g
VivotekIb9368-Ht-
VivotekIb9380-H Firmware<= 0222g
VivotekIb9380-H-
VivotekIb9388-Ht Firmware<= 0222g
VivotekIb9388-Ht-
VivotekIt9360-H Firmware<= 0222g
VivotekIt9360-H-

References

FAQ

What is CVE-2020-11949?

CVE-2020-11949 is a vulnerability with a CVSS score of 6.5 (MEDIUM). testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's ...

How severe is CVE-2020-11949?

CVE-2020-11949 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11949?

Check the references section above for vendor advisories and patch information. Affected products include: Vivotek Cc9381-Hv Firmware, Vivotek Cc9381-Hv, Vivotek Fd9360-H Firmware, Vivotek Fd9360-H, Vivotek Fd9368-Htv Firmware.