Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8006

Опубликовано: 12 апр. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the charging station do not use a number of common exploitation mitigations. In particular, there are no stack canaries and they do not use the Position Independent Executable (PIE) format.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:circontrol:raption_server:*:*:*:*:*:*:*:*
Версия до 5.11.2 (включая)

EPSS

Процентиль: 45%
0.00225
Низкий

8.8 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 8.8
github
почти 2 года назад

The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the charging station do not use a number of common exploitation mitigations. In particular, there are no stack canaries and they do not use the Position Independent Executable (PIE) format.

EPSS

Процентиль: 45%
0.00225
Низкий

8.8 High

CVSS3

Дефекты

CWE-121