Outpost24/Pyrescom-Termod-PoC

Outpost24/Pyrescom-Termod-PoC

Releases0
Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH9 HIGH

Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.

6.5 MEDIUM4 MEDIUM

Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

7.5 HIGH5 MEDIUM

Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials.