Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48362 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It is possible to initiate the attack remotely. The identifier VDB-273525 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life. |
Wed, 07 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Aug 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek
Vivotek cc8160 Vivotek cc8160 Firmware |
|
| CPEs | cpe:2.3:h:vivotek:cc8160:-:*:*:*:*:*:*:* cpe:2.3:o:vivotek:cc8160_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vivotek
Vivotek cc8160 Vivotek cc8160 Firmware |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-07T20:36:03.492Z
Reserved: 2024-08-02T21:36:34.385Z
Link: CVE-2024-7440
Updated: 2024-08-07T20:35:59.168Z
Status : Modified
Published: 2024-08-03T17:15:49.667
Modified: 2024-08-07T21:15:41.940
Link: CVE-2024-7440
No data.
OpenCVE Enrichment
No data.
EUVD