CRITICAL · 9.6

CVE-2020-8976

The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen...

Vulnerability Description

The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious request.

CVSS Score

9.6

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZigorZgr Tps200 Ng Firmware2.00
ZigorZgr Tps200 Ng1.01

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8976?

CVE-2020-8976 is a vulnerability with a CVSS score of 9.6 (CRITICAL). The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen...

How severe is CVE-2020-8976?

CVE-2020-8976 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-8976?

Check the references section above for vendor advisories and patch information. Affected products include: Zigor Zgr Tps200 Ng Firmware, Zigor Zgr Tps200 Ng.