{"api_version":"1","generated_at":"2026-07-23T13:46:21+00:00","cve":"CVE-2019-15020","urls":{"html":"https://cve.report/CVE-2019-15020","api":"https://cve.report/api/cve/CVE-2019-15020.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-15020","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-15020"},"summary":{"title":"CVE-2019-15020","description":"A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.","state":"PUBLIC","assigner":"psirt@paloaltonetworks.com","published_at":"2019-10-09 21:15:00","updated_at":"2023-02-15 02:38:00"},"problem_types":["CWE-346"],"metrics":[],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2019-15020","name":"https://security.paloaltonetworks.com/CVE-2019-15020","refsource":"MISC","tags":[],"title":"CVE-2019-15020 Command Injection in Zingbox Inspector","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-15020","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15020","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"15020","vulnerable":"1","versionEndIncluding":"1.293","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zingbox","cpe5":"inspector","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-15020","ASSIGNER":"psirt@paloaltonetworks.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Palo Alto Networks Zingbox Inspector","version":{"version_data":[{"version_value":"Zingbox Inspector, versions 1.293 and earlier."}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Command Injection"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://security.paloaltonetworks.com/CVE-2019-15020","url":"https://security.paloaltonetworks.com/CVE-2019-15020"}]},"description":{"description_data":[{"lang":"eng","value":"A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection."}]}},"nvd":{"publishedDate":"2019-10-09 21:15:00","lastModifiedDate":"2023-02-15 02:38:00","problem_types":["CWE-346"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zingbox:inspector:*:*:*:*:*:*:*:*","versionEndIncluding":"1.293","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"15020","Ordinal":"154286","Title":"CVE-2019-15020","CVE":"CVE-2019-15020","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"15020","Ordinal":"1","NoteData":"A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"15020","Ordinal":"2","NoteData":"2019-10-09","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"15020","Ordinal":"3","NoteData":"2020-02-17","Type":"Other","Title":"Modified"}]}}}