exacqVision Software - Improper Verification of Cryptographic Signature
CVE-2020-9047

6.8MEDIUM

Key Information:

Badges

👾 Exploit Exists🟡 Public PoC🟣 EPSS 17%

What is CVE-2020-9047?

A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.

Affected Version(s)

exacqVision Enterprise Manager 20.03.3.0 and prior <= 20.03.3.0

exacqVision Web Service 20.03.2.0 and prior <= 20.03.2.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

17% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Norris
.