Lucene search

K
cvelistIcscertCVELIST:CVE-2020-14505
HistoryJul 15, 2020 - 1:59 a.m.

CVE-2020-14505

2020-07-1501:59:33
CWE-77
icscert
www.cve.org

9.6 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.7%

Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.

CNA Affected

[
  {
    "product": "Advantech iView",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions 5.6 and prior"
      }
    ]
  }
]

9.6 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.7%

Related for CVELIST:CVE-2020-14505