7.8

CVE-2020-5632

InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1, Host type SiteShell for Apache Windows V1.4, V1.5, and V1.6, and Host type SiteShell for Apache Windows prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1) allow authenticated attackers to bypass access restriction and to execute arbitrary code with an elevated privilege via a specially crafted executable files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nec ≫ Infocage Siteshell SwPlatform apache_windows Version < 2.0.0.6
Nec ≫ Infocage Siteshell SwPlatform iis Version >= 2.0.0.0 < 2.0.0.6
Nec ≫ Infocage Siteshell SwPlatform apache_windows Version >= 2.1.0.0 < 2.1.0.7
Nec ≫ Infocage Siteshell SwPlatform iis Version >= 2.1.0.0 < 2.1.0.7
Nec ≫ Infocage Siteshell SwPlatform apache_windows Version >= 2.1.1.0 < 2.1.1.6
Nec ≫ Infocage Siteshell SwPlatform iis Version >= 2.1.1.0 < 2.1.1.6
Nec ≫ Infocage Siteshell SwPlatform apache_windows Version >= 3.0.0.0 < 3.0.0.11
Nec ≫ Infocage Siteshell SwPlatform iis Version >= 3.0.0.0 < 3.0.0.11
Nec ≫ Infocage Siteshell SwPlatform apache_windows Version >= 4.0.0.0 < 4.0.0.6
Nec ≫ Infocage Siteshell SwPlatform iis Version >= 4.0.0.0 < 4.0.0.6
Nec ≫ Infocage Siteshell SwPlatform apache_windows Version >= 4.1.0.0 < 4.1.0.5
Nec ≫ Infocage Siteshell SwPlatform iis Version >= 4.1.0.0 < 4.1.0.5
Nec ≫ Infocage Siteshell SwPlatform apache_windows Version >= 4.2.0.0 < 4.2.0.1
Nec ≫ Infocage Siteshell SwPlatform iis Version >= 4.2.0.0 < 4.2.0.1
Nec ≫ Infocage Siteshell Version 1.4 SwPlatform apache_windows
Nec ≫ Infocage Siteshell Version 1.4 SwPlatform iis
Nec ≫ Infocage Siteshell Version 1.5 SwPlatform apache_windows
Nec ≫ Infocage Siteshell Version 1.5 SwPlatform iis
Nec ≫ Infocage Siteshell Version 1.6 SwPlatform apache_windows
Nec ≫ Infocage Siteshell Version 1.6 SwPlatform iis
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://jpn.nec.com/infocage/siteshell/everyone_20200918.html
Vendor Advisory
https://jvn.jp/en/jp/JVN07426151/index.html
Third Party Advisory