CVE-2020-3927
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Affected (1)
Products: Changingtec: Servisign
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.19.0617 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (4)
Source: twcert@cert.org.tw
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.