ID

VAR-202011-1587


TITLE

Tianqing security isolation and information exchange system has command execution loopholes (CNVD-2020-60067)

Trust: 0.6

sources: CNVD: CNVD-2020-60067

DESCRIPTION

Tianqing Security Isolation and Information Exchange System is an access control switch device with network isolation technology independently developed by Beijing Venustech Information Technology Co., Ltd. It provides high-security isolation protection for key data. Tianqing security isolation and information exchange system has a command execution vulnerability, which can be used by attackers to execute arbitrary operating system commands.

Trust: 0.6

sources: CNVD: CNVD-2020-60067

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-60067

AFFECTED PRODUCTS

vendor:venus star informationmodel:tianqing security isolation and information exchange systemscope:eqversion:2.6

Trust: 0.6

sources: CNVD: CNVD-2020-60067

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-60067
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-60067
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:H/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-60067

EXTERNAL IDS

db:CNVDid:CNVD-2020-60067

Trust: 0.6

sources: CNVD: CNVD-2020-60067

SOURCES

db:CNVDid:CNVD-2020-60067

LAST UPDATE DATE

2022-05-04T10:14:57.859000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-60067date:2020-11-02T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-60067date:2020-11-01T00:00:00