HIGH · 7.2

CVE-2020-16205

Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2...

Vulnerability Description

Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GeutebrueckG-Cam Ebc-2110 Firmware1.12.0.25
GeutebrueckG-Cam Ebc-2111 Firmware1.12.0.25
GeutebrueckG-Cam Efd-2240 Firmware1.12.0.25
GeutebrueckG-Cam Efd-2241 Firmware1.12.0.25
GeutebrueckG-Cam Efd-2250 Firmware1.12.0.25
GeutebrueckG-Cam Ethc-2230 Firmware1.12.0.25
GeutebrueckG-Cam Ethc-2239 Firmware1.12.0.25
GeutebrueckG-Cam Ethc-2240 Firmware1.12.0.25
GeutebrueckG-Cam Ethc-2249 Firmware1.12.0.25
GeutebrueckG-Cam Ewpc-2270 Firmware1.12.0.25
GeutebrueckG-Code Eec-2400 Firmware1.12.0.25
GeutebrueckG-Cam Ebc-2110-
GeutebrueckG-Cam Ebc-2111-
GeutebrueckG-Cam Efd-2240-
GeutebrueckG-Cam Efd-2241-
GeutebrueckG-Cam Efd-2250-
GeutebrueckG-Cam Ethc-2230-
GeutebrueckG-Cam Ethc-2239-
GeutebrueckG-Cam Ethc-2240-
GeutebrueckG-Cam Ethc-2249-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-16205?

CVE-2020-16205 is a vulnerability with a CVSS score of 7.2 (HIGH). Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2...

How severe is CVE-2020-16205?

CVE-2020-16205 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-16205?

Check the references section above for vendor advisories and patch information. Affected products include: Geutebrueck G-Cam Ebc-2110 Firmware, Geutebrueck G-Cam Ebc-2111 Firmware, Geutebrueck G-Cam Efd-2240 Firmware, Geutebrueck G-Cam Efd-2241 Firmware, Geutebrueck G-Cam Efd-2250 Firmware.