Remote Code Execution Vulnerability in Technicolor TC7337NET Devices
CVE-2020-10376

9.8CRITICAL

Key Information:

Vendor
CVE Published:
11 March 2020

What is CVE-2020-10376?

The Technicolor TC7337NET devices, specifically version 08.89.17.23.03, are susceptible to a vulnerability that permits unauthorized remote attackers to intercept sensitive information. By leveraging network sniffing techniques, attackers can capture the 'Authorization: Basic' HTTP header, which may contain user credentials. This exploitation leads to an increased risk of unauthorized access to user accounts. It is imperative for users of these devices to adopt appropriate security measures to mitigate this risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.