Input Parameter Flaw in Vivo ABE Service
CVE-2020-12487
7HIGH
Summary
CVE-2020-12487 represents a significant security vulnerability within the ABE service developed by Vivo. This flaw stems from inadequate input parameter validation, allowing an attacker to craft and submit malicious commands. When these inputs are improperly verified, it may lead to the execution of arbitrary commands with root privileges, potentially compromising the integrity and security of the affected systems. It is critical for users of the ABE service to assess their exposure and apply mitigations as provided in the security advisory.
Affected Version(s)
ABE Versions earlier than 4.4.0.9
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved