Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15492

Опубликовано: 23 июл. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:inneo:startup_tools:*:*:*:*:*:*:*:*
Версия от 12.0.66.3784 (включая) до 13.0.70.3804 (включая)

EPSS

Процентиль: 97%
0.37735
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.

EPSS

Процентиль: 97%
0.37735
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22