Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10055

Опубликовано: 14 авг. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 9.3
EPSS Низкий

Описание

A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:desigo_consumption_control:3.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_consumption_control:4.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_consumption_control_compact:3.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_consumption_control_compact:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.02702
Низкий

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-94
CWE-94

Связанные уязвимости

github
больше 3 лет назад

A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.

EPSS

Процентиль: 86%
0.02702
Низкий

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-94
CWE-94