VulnerabilityModified
CVE-2020-36531
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22.
HIGH 8.8EPSS 0.81%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-1236
- Affected
- ibm/sevone network performance management
- Source
- cna@vuldb.com
References
- http://seclists.org/fulldisclosure/2020/Oct/5Mailing List, Third Party Advisory
- https://vuldb.com/?id.162263Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Oct/5Mailing List, Third Party Advisory
- https://vuldb.com/?id.162263Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.