Iteris maintains a specialized traffic management and intelligent transportation systems platform centered on its Vantage Velocity product line, which encompasses both application and firmware components. The observed vulnerability exposure recurs around web application input handling and command-injection risks alongside credential and access-control weaknesses, reflecting the complexity of networked infrastructure software managing operational commands and user input. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iteris over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9024CRITICAL Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as | Feb 17, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-9020CRITICAL Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field. | Feb 17, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-9023CRITICAL Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User e | Feb 17, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-9025MEDIUM Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script. | Feb 17, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iteris.
Media articles that mention a CVE ID that affects a product developed by Iteris — matched by CVE ID, not by vendor name.