Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2020-9025
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
0
Attacker Value
Unknown
CVE-2020-9023
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.
0
Attacker Value
Unknown
CVE-2020-9020
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.
0
Attacker Value
Unknown
CVE-2020-9024
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.
0