CVE-2020-3927

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:changingtec:servisign:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:31

Type Values Removed Values Added
CVSS v2 : 8.5
v3 : 7.5
v2 : 8.5
v3 : 8.3
References () https://tvn.twcert.org.tw/taiwanvn/TVN-201910007 - Third Party Advisory () https://tvn.twcert.org.tw/taiwanvn/TVN-201910007 - Third Party Advisory
References () https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce - Third Party Advisory () https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce - Third Party Advisory

Information

Published : 2020-02-03 11:15

Updated : 2024-11-21 05:31


NVD link : CVE-2020-3927

Mitre link : CVE-2020-3927

CVE.ORG link : CVE-2020-3927


JSON object : View

Products Affected

changingtec

  • servisign

microsoft

  • windows
CWE
CWE-552

Files or Directories Accessible to External Parties