{"api_version":"1","generated_at":"2026-07-23T13:48:50+00:00","cve":"CVE-2020-3925","urls":{"html":"https://cve.report/CVE-2020-3925","api":"https://cve.report/api/cve/CVE-2020-3925.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-3925","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-3925"},"summary":{"title":"CVE-2020-3925","description":"A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts.","state":"PUBLIC","assigner":"cve@cert.org.tw","published_at":"2020-02-03 11:15:00","updated_at":"2020-02-12 14:55:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://tvn.twcert.org.tw/taiwanvn/TVN-201910005","name":"N/A","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"台灣漏洞紀錄平台 Taiwan Vulnerability Note","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce","name":"https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce","refsource":"MISC","tags":["Third Party Advisory"],"title":"CHT Security Financial Security Assessment Team Discovered Insecure API in Well-Known Domestic Cross-Platform Digital Signature Plugin｜中華資安國際 CHT Security Co., Ltd.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-3925","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-3925","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"3925","vulnerable":"1","versionEndIncluding":"1.0.19.0617","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"changingtec","cpe5":"servisign","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"3925","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"3925","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"TWCERT/CC","ASSIGNER":"cve@cert.org.tw","DATE_PUBLIC":"2020-02-03T10:00:00.000Z","ID":"CVE-2020-3925","STATE":"PUBLIC","TITLE":"ServiSign Windows Versions- Remote Code Execution via  LoadLibrary "},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"ServiSign Windows versions ","version":{"version_data":[{"version_affected":"<=","version_name":"0","version_value":"1.0.19.0617"}]}}]},"vendor_name":"CHANGING"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Remote Code Execution"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://tvn.twcert.org.tw/taiwanvn/TVN-201910005","name":"https://tvn.twcert.org.tw/taiwanvn/TVN-201910005"},{"refsource":"MISC","name":"https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce","url":"https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce"}]},"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2020-02-03 11:15:00","lastModifiedDate":"2020-02-12 14:55:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:changingtec:servisign:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.19.0617","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"3925","Ordinal":"163728","Title":"CVE-2020-3925","CVE":"CVE-2020-3925","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"3925","Ordinal":"1","NoteData":"A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"3925","Ordinal":"2","NoteData":"2020-02-03","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"3925","Ordinal":"3","NoteData":"2020-02-11","Type":"Other","Title":"Modified"}]}}}