Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service.
References
Link | Resource |
---|---|
https://moica.nat.gov.tw/rac_plugin.html | Patch Vendor Advisory |
https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html | Third Party Advisory |
https://moica.nat.gov.tw/rac_plugin.html | Patch Vendor Advisory |
https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://moica.nat.gov.tw/rac_plugin.html - Patch, Vendor Advisory | |
References | () https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html - Third Party Advisory |
Information
Published : 2022-03-01 02:15
Updated : 2024-11-21 05:00
NVD link : CVE-2020-12775
Mitre link : CVE-2020-12775
CVE.ORG link : CVE-2020-12775
JSON object : View
Products Affected
moica
- hicos
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')