Skip to content
Noroxi

iteris records

4 published records for vendor iteris.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

4 records
  • Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell met

    CriticalCVSS 9.8No exploitEPSS 3%

    iteris · vantage velocity firmwareFeb 17, 2020

  • Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by c

    CriticalCVSS 9.8No exploitEPSS 2%

    iteris · vantage velocity firmwareFeb 17, 2020

  • CVE-2020-9023
    39Monitor

    Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (Us

    CriticalCVSS 9.8No exploitEPSS 1%

    iteris · vantage velocity firmwareFeb 17, 2020

  • CVE-2020-9025
    24Monitor

    Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /

    MediumCVSS 6.1No exploitEPSS 1%

    iteris · vantage velocity firmwareFeb 17, 2020