VulnerabilityModified
CVE-2020-7778
The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
HIGH 7.3EPSS 2.42%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
- CVSS 3.1
- 7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 2.42% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- systeminformation/systeminformation
- Source
- report@snyk.io
References
- https://gist.github.com/EffectRenan/b434438938eed0b21b376cedf5c81e80Exploit, Third Party Advisory
- https://github.com/sebhildebrandt/systeminformation/blob/master/lib/internet.jsExploit, Third Party Advisory
- https://github.com/sebhildebrandt/systeminformation/commit/11103a447ab9550c25f1fbec7e6d903720b3fea8%23diff-970ae648187190f86bafc8f193b7538200eba164fad0674428b6487582c089ccPatch, Third Party Advisory
- https://github.com/sebhildebrandt/systeminformation/commit/73dce8d717ca9c3b7b0d0688254b8213b957f0fa%23diff-970ae648187190f86bafc8f193b7538200eba164fad0674428b6487582c089ccPatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SYSTEMINFORMATION-1043753Third Party Advisory
- https://gist.github.com/EffectRenan/b434438938eed0b21b376cedf5c81e80Exploit, Third Party Advisory
- https://github.com/sebhildebrandt/systeminformation/blob/master/lib/internet.jsExploit, Third Party Advisory
- https://github.com/sebhildebrandt/systeminformation/commit/11103a447ab9550c25f1fbec7e6d903720b3fea8%23diff-970ae648187190f86bafc8f193b7538200eba164fad0674428b6487582c089ccPatch, Third Party Advisory
- https://github.com/sebhildebrandt/systeminformation/commit/73dce8d717ca9c3b7b0d0688254b8213b957f0fa%23diff-970ae648187190f86bafc8f193b7538200eba164fad0674428b6487582c089ccPatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SYSTEMINFORMATION-1043753Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.