CVE Feed

    Dashboard / CVE / CVE-2020-24217

    CVE-2020-24217

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.

    Published:Oct 6, 2020
    Last Modified:Nov 21, 2024
    EPS:Oct 6, 2020
    EPSS Score:0.28283
    CVSS Score:9.8

    Affected Products

    Vendor
    Jtechdigital
    Product
    H.264 Iptv Encoder 1080p\@60hz
    Vendor
    Jtechdigital
    Product
    H.264 Iptv Encoder 1080p\@60hz Firmware
    Vendor
    Provideoinstruments
    Product
    Vecaster-4k-hevc
    Vendor
    Provideoinstruments
    Product
    Vecaster-4k-hevc Firmware
    Vendor
    Provideoinstruments
    Product
    Vecaster-hd-h264
    Vendor
    Provideoinstruments
    Product
    Vecaster-hd-h264 Firmware
    Vendor
    Provideoinstruments
    Product
    Vecaster-hd-hevc
    Vendor
    Provideoinstruments
    Product
    Vecaster-hd-hevc Firmware
    Vendor
    Provideoinstruments
    Product
    Vecaster-hd-sdi
    Vendor
    Provideoinstruments
    Product
    Vecaster-hd-sdi Firmware
    Vendor
    Szuray
    Product
    Iptv\/h.264 Video Encoder Firmware
    Vendor
    Szuray
    Product
    Iptv\/h.265 Video Encoder Firmware
    Vendor
    Szuray
    Product
    Uaioe264-1u
    Vendor
    Szuray
    Product
    Uaioe265-1u
    Vendor
    Szuray
    Product
    Uce264-1-mini
    Vendor
    Szuray
    Product
    Uce264-1wb-mini
    Vendor
    Szuray
    Product
    Uce264-4-1u
    Vendor
    Szuray
    Product
    Uce264-8-1u
    Vendor
    Szuray
    Product
    Uhae264-16
    Vendor
    Szuray
    Product
    Uhae265-1-mini
    Vendor
    Szuray
    Product
    Uhae265-1wb-mini
    Vendor
    Szuray
    Product
    Uhae265-4-1u
    Vendor
    Szuray
    Product
    Uhce264-1
    Vendor
    Szuray
    Product
    Uhce264-16p32
    Vendor
    Szuray
    Product
    Uhce264-1p2
    Vendor
    Szuray
    Product
    Uhce264-1p2-1u
    Vendor
    Szuray
    Product
    Uhce264-1s
    Vendor
    Szuray
    Product
    Uhce264-1w
    Vendor
    Szuray
    Product
    Uhce264-1ws
    Vendor
    Szuray
    Product
    Uhce264-4p8
    Vendor
    Szuray
    Product
    Uhe264-1-4k
    Vendor
    Szuray
    Product
    Uhe264-16
    Vendor
    Szuray
    Product
    Uhe264-16l-3u
    Vendor
    Szuray
    Product
    Uhe264-16s-2u
    Vendor
    Szuray
    Product
    Uhe264-1l
    Vendor
    Szuray
    Product
    Uhe264-1l-4k
    Vendor
    Szuray
    Product
    Uhe264-1lw
    Vendor
    Szuray
    Product
    Uhe264-1s
    Vendor
    Szuray
    Product
    Uhe264-1s-mini
    Vendor
    Szuray
    Product
    Uhe264-1w-mini
    Vendor
    Szuray
    Product
    Uhe264-1wb-4g
    Vendor
    Szuray
    Product
    Uhe264-1wb-mini
    Vendor
    Szuray
    Product
    Uhe264-1wbs-2b
    Vendor
    Szuray
    Product
    Uhe264-1wbs-mini
    Vendor
    Szuray
    Product
    Uhe264-1ws-mini
    Vendor
    Szuray
    Product
    Uhe264-2-1u
    Vendor
    Szuray
    Product
    Uhe264-4
    Vendor
    Szuray
    Product
    Uhe264-4-1u
    Vendor
    Szuray
    Product
    Uhe264-4l-1u
    Vendor
    Szuray
    Product
    Uhe264-8
    Vendor
    Szuray
    Product
    Uhe264-8-1u
    Vendor
    Szuray
    Product
    Uhe264-8l-3u
    Vendor
    Szuray
    Product
    Uhe264-8s-2u
    Vendor
    Szuray
    Product
    Uhe265-1
    Vendor
    Szuray
    Product
    Uhe265-1-1u
    Vendor
    Szuray
    Product
    Uhe265-1-4k
    Vendor
    Szuray
    Product
    Uhe265-1-mini
    Vendor
    Szuray
    Product
    Uhe265-16-3u
    Vendor
    Szuray
    Product
    Uhe265-16l-3u
    Vendor
    Szuray
    Product
    Uhe265-1l
    Vendor
    Szuray
    Product
    Uhe265-1lw
    Vendor
    Szuray
    Product
    Uhe265-1s-4k
    Vendor
    Szuray
    Product
    Uhe265-1s-mini
    Vendor
    Szuray
    Product
    Uhe265-1w
    Vendor
    Szuray
    Product
    Uhe265-1w-4k
    Vendor
    Szuray
    Product
    Uhe265-1w-mini
    Vendor
    Szuray
    Product
    Uhe265-1wb-4g
    Vendor
    Szuray
    Product
    Uhe265-1wb-mini
    Vendor
    Szuray
    Product
    Uhe265-1wbs-mini
    Vendor
    Szuray
    Product
    Uhe265-2-1u
    Vendor
    Szuray
    Product
    Uhe265-4
    Vendor
    Szuray
    Product
    Uhe265-4-1u
    Vendor
    Szuray
    Product
    Uhe265-4s
    Vendor
    Szuray
    Product
    Uhe265-4s-1u
    Vendor
    Szuray
    Product
    Uhe265-8-1u
    Vendor
    Szuray
    Product
    Uhe265-8l-3u
    Vendor
    Szuray
    Product
    Uhe265-8s-1u
    Vendor
    Szuray
    Product
    Uhse265-1u
    Vendor
    Szuray
    Product
    Use264-16-3u
    Vendor
    Szuray
    Product
    Use264-1l
    Vendor
    Szuray
    Product
    Use264-1l-1u
    Vendor
    Szuray
    Product
    Use264-1l-mini
    Vendor
    Szuray
    Product
    Use264-1lw
    Vendor
    Szuray
    Product
    Use264-1wb-l
    Vendor
    Szuray
    Product
    Use264-4l-1u
    Vendor
    Szuray
    Product
    Use264-8-1u
    Vendor
    Szuray
    Product
    Use265-1-1u
    Vendor
    Szuray
    Product
    Use265-1-mini
    Vendor
    Szuray
    Product
    Use265-16l-3u
    Vendor
    Szuray
    Product
    Use265-1l
    Vendor
    Szuray
    Product
    Use265-1l-1u
    Vendor
    Szuray
    Product
    Use265-1l-mini
    Vendor
    Szuray
    Product
    Use265-1lw
    Vendor
    Szuray
    Product
    Use265-1w-mini
    Vendor
    Szuray
    Product
    Use265-1wb-4g
    Vendor
    Szuray
    Product
    Use265-1wb-l
    Vendor
    Szuray
    Product
    Use265-1wb-mini
    Vendor
    Szuray
    Product
    Use265-2-1u
    Vendor
    Szuray
    Product
    Use265-4-1u
    Vendor
    Szuray
    Product
    Use265-4l-1u
    Vendor
    Szuray
    Product
    Use265-8-1u
    Vendor
    Szuray
    Product
    Uve264-1l
    Vendor
    Szuray
    Product
    Uve264-1lw
    Vendor
    Szuray
    Product
    Uve265-1
    Vendor
    Szuray
    Product
    Uve265-1w

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High