Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6787

Опубликовано: 25 мар. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.9
EPSS Низкий

Описание

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including version 1.7.6.079 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bosch:video_client:*:*:*:*:*:*:*:*
Версия до 1.7.6.079 (включая)

EPSS

Процентиль: 19%
0.00061
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-427
CWE-427

Связанные уязвимости

github
больше 3 лет назад

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including version 1.7.6.079 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.

EPSS

Процентиль: 19%
0.00061
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-427
CWE-427