CyberSec.Space Logo
返回 CVE 浏览器

CVE-2020-24217

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1920%
EPSS Percentile6.41th
Published2020年10月6日
Last Modified2024年11月21日

Vulnerability Description

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.

Affected Platforms (CPE)

💻
Szuray

Iptv\/h.264 Video Encoder Firmware

All versions
💻
Szuray

Iptv\/h.265 Video Encoder Firmware

All versions
💻
Jtechdigital

H.264 Iptv Encoder 1080p\@60hz Firmware

All versions
💻
Provideoinstruments

Vecaster Hd H264 Firmware

All versions
💻
Provideoinstruments

Vecaster Hd Hevc Firmware

All versions
💻
Provideoinstruments

Vecaster 4k Hevc Firmware

All versions
💻
Provideoinstruments

Vecaster Hd Sdi Firmware

All versions

References & Advisories

相关漏洞威胁