Lucene search

K
cveMitreCVE-2020-8515
HistoryFeb 01, 2020 - 1:15 p.m.

CVE-2020-8515

2020-02-0113:15:12
CWE-78
mitre
web.nvd.nist.gov
1394
In Wild
7
cve-2020-8515
draytek vigor
vigor2960
vigor3900
vigor300b
remote code execution
root access
security vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.973

Percentile

99.9%

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

Affected configurations

Nvd
Node
draytekvigor2960_firmwareMatch1.3.1beta
AND
draytekvigor2960Match-
Node
draytekvigor300b_firmwareMatch1.3.3beta
OR
draytekvigor300b_firmwareMatch1.4.2.1beta
OR
draytekvigor300b_firmwareMatch1.4.4beta
AND
draytekvigor300bMatch-
Node
draytekvigor3900_firmwareMatch1.4.4beta
AND
draytekvigor3900Match-
VendorProductVersionCPE
draytekvigor2960_firmware1.3.1cpe:2.3:o:draytek:vigor2960_firmware:1.3.1:beta:*:*:*:*:*:*
draytekvigor2960-cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*
draytekvigor300b_firmware1.3.3cpe:2.3:o:draytek:vigor300b_firmware:1.3.3:beta:*:*:*:*:*:*
draytekvigor300b_firmware1.4.2.1cpe:2.3:o:draytek:vigor300b_firmware:1.4.2.1:beta:*:*:*:*:*:*
draytekvigor300b_firmware1.4.4cpe:2.3:o:draytek:vigor300b_firmware:1.4.4:beta:*:*:*:*:*:*
draytekvigor300b-cpe:2.3:h:draytek:vigor300b:-:*:*:*:*:*:*:*
draytekvigor3900_firmware1.4.4cpe:2.3:o:draytek:vigor3900_firmware:1.4.4:beta:*:*:*:*:*:*
draytekvigor3900-cpe:2.3:h:draytek:vigor3900:-:*:*:*:*:*:*:*

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.973

Percentile

99.9%