HIGH · 8.8

CVE-2020-11950

VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For e...

Vulnerability Description

VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
VivotekCc9381-Hv Firmware<= 0222g
VivotekCc9381-Hv-
VivotekFd9360-H Firmware<= 0222g
VivotekFd9360-H-
VivotekFd9368-Htv Firmware<= 0222g
VivotekFd9368-Htv-
VivotekFd9380-H Firmware<= 0222g
VivotekFd9380-H-
VivotekFd9388-Htv Firmware<= 0222g
VivotekFd9388-Htv-
VivotekIb9360-H Firmware<= 0222g
VivotekIb9360-H-
VivotekIb9368-Ht Firmware<= 0222g
VivotekIb9368-Ht-
VivotekIb9380-H Firmware<= 0222g
VivotekIb9380-H-
VivotekIb9388-Ht Firmware<= 0222g
VivotekIb9388-Ht-
VivotekIt9360-H Firmware<= 0222g
VivotekIt9360-H-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11950?

CVE-2020-11950 is a vulnerability with a CVSS score of 8.8 (HIGH). VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For e...

How severe is CVE-2020-11950?

CVE-2020-11950 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11950?

Check the references section above for vendor advisories and patch information. Affected products include: Vivotek Cc9381-Hv Firmware, Vivotek Cc9381-Hv, Vivotek Fd9360-H Firmware, Vivotek Fd9360-H, Vivotek Fd9368-Htv Firmware.