← Back

CVE-2020-26155

nvd nist
Published: Mar 18, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak permissions, could enable an attacker to perform a DLL hijacking attack.

Affected (8)

6 products
Block Safe Firmware
Cryptoserver Cp5 Firmware
Cryptoserver Cp5 Vs Nfd Firmware
Paymentserver Firmware
Paymentserver Hybrid Firmware
Securityserver Firmware
Configuration A
8 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Utimaco
Version 2.0.0
Version 3.0.0
Utimaco
Version 5.0.0.0
Version 5.1.0.0
Version 5.1.0.0
From 3.0 to 4.31.0
From 3.0 to 4.33.0
From 3.0 to 4.31.1
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.