CVE-2020-7847
—CVSS 3.1
8.0 high
EPSS
<1%p42
Published
()
Modified
Description
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.
- Vendors
- iptime
- Products
- nas-i firmware, nas-ii firmware, nas-iie firmware, nas101 firmware, nas1dual firmware, nas2dual firmware, nas3 firmware, nas4 firmware, nas4dual firmware
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.