CVE-2019-12182

Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:safescan:ta-8010_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safescan:ta-8010:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:safescan:ta-8015_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safescan:ta-8015:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:safescan:ta-8020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safescan:ta-8020:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:safescan:ta-8025_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safescan:ta-8025:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:safescan:ta-8030_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safescan:ta-8030:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:safescan:ta-8035_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safescan:ta-8035:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:safescan:tm-616_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:safescan:tm-616:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:22

Type Values Removed Values Added
References () https://github.com/ProCheckUp/SafeScan - Exploit, Third Party Advisory () https://github.com/ProCheckUp/SafeScan - Exploit, Third Party Advisory
References () https://procheckup.com/blogs/posts/2020/february/remote-code-execution-on-biometric-iot-devices/ - Exploit, Third Party Advisory () https://procheckup.com/blogs/posts/2020/february/remote-code-execution-on-biometric-iot-devices/ - Exploit, Third Party Advisory
References () https://safescan.com/ - Product () https://safescan.com/ - Product
References () https://support.timemoto.com/en/s/safescan-time-clock-systems/a/firmware-update-7-dot-03-dot-100-ta8000-14 - Vendor Advisory () https://support.timemoto.com/en/s/safescan-time-clock-systems/a/firmware-update-7-dot-03-dot-100-ta8000-14 - Vendor Advisory

Information

Published : 2020-03-13 17:15

Updated : 2024-11-21 04:22


NVD link : CVE-2019-12182

Mitre link : CVE-2019-12182

CVE.ORG link : CVE-2019-12182


JSON object : View

Products Affected

safescan

  • ta-8010_firmware
  • ta-8015
  • ta-8025_firmware
  • ta-8030_firmware
  • tm-616_firmware
  • ta-8010
  • ta-8025
  • ta-8030
  • ta-8015_firmware
  • ta-8020
  • ta-8035_firmware
  • ta-8020_firmware
  • ta-8035
  • tm-616
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')