CVE-2020-9047
Published: Jun 26, 2020
Modified: Aug 4, 2024
CVSS v3.1
6.8
Description
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.
| Vendor | Product | Versions |
|---|---|---|
Johnson Controls | exacqVision Web Service versions 20.03.2.0 and prior | affected unspecified - <= 20.03.2.0 |
Johnson Controls | exacqVision Enterprise Manager versions 20.03.3.0 and prior | affected unspecified - <= 20.03.3.0 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now