CVE-2020-7847: Malicious File Upload
Published Feb 23, 2021
·Updated
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.
Affected Software
18 affected components
IPTIME Nas-i Firmware<1.4.36
IPTIME Nas-i
IPTIME Nas-ii Firmware<1.4.36
IPTIME Nas-ii
IPTIME Nas-iie Firmware<1.4.36
IPTIME Nas-iie
IPTIME Nas101 Firmware<1.4.36
IPTIME Nas101
IPTIME Nas1dual Firmware<1.4.36
IPTIME NAS1DUAL
IPTIME Nas2dual Firmware<1.4.36
IPTIME NAS2dual
IPTIME Nas3 Firmware<1.4.36
IPTIME Nas3
IPTIME Nas4 Firmware<1.4.36
IPTIME Nas4
IPTIME Nas4dual Firmware<1.4.36
IPTIME Nas4dual
Event History
Feb 23, 2021
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-7847?
CVE-2020-7847 is an arbitrary file upload vulnerability in the ipTIME NAS product.
2
How does CVE-2020-7847 impact the ipTIME NAS?
CVE-2020-7847 allows for remote code execution on the ipTIME NAS.
3
What is the severity level of CVE-2020-7847?
CVE-2020-7847 has a severity of 8 (high).
4
Which version of ipTIME NAS is affected by CVE-2020-7847?
ipTIME NAS version 1.4.36 is affected by CVE-2020-7847.
5
How can I fix the arbitrary file upload vulnerability in ipTIME NAS?
To fix the arbitrary file upload vulnerability in ipTIME NAS, it is recommended to update to a version that is not affected, such as a version higher than 1.4.36.