8.5

CVE-2020-3927

ServiSign Windows Versions- Arbitrary File Deletion

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ChangingtecServisign Version <= 1.0.19.0617
   MicrosoftWindows Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 8.5 10 7.8
AV:N/AC:L/Au:N/C:N/I:C/A:P
twcert@cert.org.tw 8.3 1.6 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce
Third Party Advisory
https://tvn.twcert.org.tw/taiwanvn/TVN-201910007
Third Party Advisory