8.5
CVE-2020-3927
- EPSS 1.21%
- Veröffentlicht 03.02.2020 11:15:12
- Zuletzt bearbeitet 21.11.2024 05:31:58
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
ServiSign Windows Versions- Arbitrary File Deletion
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Changingtec ≫ Servisign Version <= 1.0.19.0617
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.21% | 0.643 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 8.5 | 10 | 7.8 |
AV:N/AC:L/Au:N/C:N/I:C/A:P
|
| twcert@cert.org.tw | 8.3 | 1.6 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce
https://tvn.twcert.org.tw/taiwanvn/TVN-201910007