exacqVision Software - Improper Verification of Cryptographic Signature
CVE-2020-9047
Key Information:
- Vendor
Johnson Controls
- Status
- Vendor
- CVE Published:
- 26 June 2020
Badges
What is CVE-2020-9047?
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.
Affected Version(s)
exacqVision Enterprise Manager 20.03.3.0 and prior <= 20.03.3.0
exacqVision Web Service 20.03.2.0 and prior <= 20.03.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
17% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved