CVE-2020-3925
A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.77% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- changingtec/servisign
- Source
- twcert@cert.org.tw
References
- https://tvn.twcert.org.tw/taiwanvn/TVN-201910005Third Party Advisory
- https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ceThird Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201910005Third Party Advisory
- https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ceThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.