{"api_version":"1","generated_at":"2026-07-23T12:37:02+00:00","cve":"CVE-2020-12775","urls":{"html":"https://cve.report/CVE-2020-12775","api":"https://cve.report/api/cve/CVE-2020-12775.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-12775","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-12775"},"summary":{"title":"CVE-2020-12775","description":"Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service.","state":"PUBLIC","assigner":"cve@cert.org.tw","published_at":"2022-03-01 02:15:00","updated_at":"2022-03-10 14:28:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://moica.nat.gov.tw/rac_plugin.html","name":"https://moica.nat.gov.tw/rac_plugin.html","refsource":"MISC","tags":[],"title":"MOICA內政部憑證管理中心-跨平台網頁元件下載","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html","refsource":"MISC","tags":[],"title":"TWCERT/CC台灣電腦網路危機處理暨協調中心|企業資安通報協處|資安情資分享|漏洞通報|資安聯盟|資安電子報-Hicos自然人憑證客戶端元件版本 - Command Injection","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-12775","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-12775","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"12775","vulnerable":"1","versionEndIncluding":"1.3.4.12","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moica","cpe5":"hicos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"macos","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"12775","vulnerable":"1","versionEndIncluding":"3.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moica","cpe5":"hicos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"TWCERT/CC","ASSIGNER":"cve@cert.org.tw","DATE_PUBLIC":"2022-01-31T01:27:00.000Z","ID":"CVE-2020-12775","STATE":"PUBLIC","TITLE":"Hicos citizen certificate client-side component - Command Injection"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"citizen certificate client-side component","version":{"version_data":[{"platform":"Windows","version_affected":"<=","version_value":"3.0.0"},{"platform":"Mac","version_affected":"<=","version_value":"1.3.4.12"}]}}]},"vendor_name":"Hicos"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-78 OS Command Injection"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html"},{"refsource":"MISC","url":"https://moica.nat.gov.tw/rac_plugin.html","name":"https://moica.nat.gov.tw/rac_plugin.html"}]},"solution":[{"lang":"eng","value":"Download latest version"}],"source":{"advisory":"TVN-202201006","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-03-01 02:15:00","lastModifiedDate":"2022-03-10 14:28:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moica:hicos:*:*:*:*:*:macos:*:*","versionEndIncluding":"1.3.4.12","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moica:hicos:*:*:*:*:*:windows:*:*","versionEndIncluding":"3.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"12775","Ordinal":"173947","Title":"CVE-2020-12775","CVE":"CVE-2020-12775","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"12775","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}