CVE-2020-9021

EUVD-2020-29851
Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
postoaktrafficawam_bluetooth_field_device_firmware
2011.3
postoaktrafficawam_bluetooth_field_device_firmware
7400v2.02.01.2019:v2.02
postoaktrafficawam_bluetooth_field_device_firmware
7400v2.08.21.2018:v2.08
postoaktrafficawam_bluetooth_field_device_firmware
7800sd.2012.12.5:sd.2012
postoaktrafficawam_bluetooth_field_device_firmware
7800sd.2015.1.16:sd.2015
𝑥
= Vulnerable software versions