CVE-2020-3925
Summary
| CVE | CVE-2020-3925 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-03 11:15:00 UTC |
| Updated | 2020-02-12 14:55:00 UTC |
| Description | A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 台灣漏洞紀錄平台 Taiwan Vulnerability Note | CONFIRM | tvn.twcert.org.tw | Third Party Advisory |
| CHT Security Financial Security Assessment Team Discovered Insecure API in Well-Known Domestic Cross-Platform Digital Signature Plugin|中華資安國際 CHT Security Co., Ltd. | MISC | www.chtsecurity.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.