Lucene search

K
cveHCLCVE-2020-14244
HistoryDec 14, 2020 - 4:15 p.m.

CVE-2020-14244

2020-12-1416:15:11
CWE-787
HCL
web.nvd.nist.gov
28
4
cve-2020-14244
vulnerability
mime handling
domino server
remote code injection
stack buffer overflow
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.006

Percentile

78.3%

A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which would execute with the privileges of the server.

Affected configurations

Nvd
Node
hcltechdominoRange9.0.010.0.1
OR
hcltechdominoMatch10.0.1fix_pack_1
OR
hcltechdominoMatch10.0.1fix_pack_2
OR
hcltechdominoMatch10.0.1fix_pack_3
VendorProductVersionCPE
hcltechdomino*cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:*
hcltechdomino10.0.1cpe:2.3:a:hcltech:domino:10.0.1:fix_pack_1:*:*:*:*:*:*
hcltechdomino10.0.1cpe:2.3:a:hcltech:domino:10.0.1:fix_pack_2:*:*:*:*:*:*
hcltechdomino10.0.1cpe:2.3:a:hcltech:domino:10.0.1:fix_pack_3:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "HCL Domino",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "v9, v10"
      }
    ]
  }
]

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.006

Percentile

78.3%

Related for CVE-2020-14244