CVE Database
/

CVE-2020-9047

Back to search

CVE-2020-9047

Published: Jun 26, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

6.8

MEDIUM

Description

A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.

VendorProductVersions

Johnson Controls

exacqVision Web Service versions 20.03.2.0 and prior

affected
unspecified - <= 20.03.2.0

Johnson Controls

exacqVision Enterprise Manager versions 20.03.3.0 and prior

affected
unspecified - <= 20.03.3.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L

Attack Vector

Network

Attack Complexity

High

Privileges Required

High

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

High

Availability

Low

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now