CVE-2020-3926

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:changingtec:servisign:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:31

Type Values Removed Values Added
CVSS v2 : 7.8
v3 : 7.5
v2 : 7.8
v3 : 6.1
References () https://tvn.twcert.org.tw/taiwanvn/TVN-201910006 - Third Party Advisory () https://tvn.twcert.org.tw/taiwanvn/TVN-201910006 - Third Party Advisory
References () https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce - Third Party Advisory () https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce - Third Party Advisory

Information

Published : 2020-02-03 11:15

Updated : 2024-11-21 05:31


NVD link : CVE-2020-3926

Mitre link : CVE-2020-3926

CVE.ORG link : CVE-2020-3926


JSON object : View

Products Affected

changingtec

  • servisign

microsoft

  • windows
CWE
CWE-552

Files or Directories Accessible to External Parties