Vulnerability Description
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Evertz | 3080Ipx Firmware | exe-guest-v1.2-r26125 |
| Evertz | 3080Ipx | - |
| Evertz | 7801Fc Firmware | 1.3 |
| Evertz | 7801Fc | - |
| Evertz | 7890Ixg Firmware | v494 |
| Evertz | 7890Ixg | - |
Related Weaknesses (CWE)
References
- https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multiExploit
- https://sku11army.blogspot.com/2020/02/evertz-path-transversal-arbitrary-file.htPermissions Required
- https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multiExploit
- https://sku11army.blogspot.com/2020/02/evertz-path-transversal-arbitrary-file.htPermissions Required
FAQ
What is CVE-2020-22159?
CVE-2020-22159 is a vulnerability with a CVSS score of 8.8 (HIGH). EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any cr...
How severe is CVE-2020-22159?
CVE-2020-22159 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-22159?
Check the references section above for vendor advisories and patch information. Affected products include: Evertz 3080Ipx Firmware, Evertz 3080Ipx, Evertz 7801Fc Firmware, Evertz 7801Fc, Evertz 7890Ixg Firmware.