Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8274

Опубликовано: 06 янв. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:citrix:secure_mail:*:*:*:*:*:android:*:*
Версия до 20.11.0 (исключая)

EPSS

Процентиль: 77%
0.01036
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-94
CWE-94

Связанные уязвимости

github
больше 3 лет назад

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

EPSS

Процентиль: 77%
0.01036
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-94
CWE-94