Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10051

Опубликовано: 09 сент. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to inject arbitrary commands that are execeuted instead of the legitimate service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:siemens:simatic_rtls_locating_manager:*:*:*:*:*:*:*:*
Версия до 2.10.2 (исключая)

EPSS

Процентиль: 12%
0.00039
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-428
CWE-428

Связанные уязвимости

github
больше 3 лет назад

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to inject arbitrary commands that are execeuted instead of the legitimate service.

EPSS

Процентиль: 12%
0.00039
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-428
CWE-428