{"api_version":"1","generated_at":"2026-07-23T14:26:46+00:00","cve":"CVE-2020-5555","urls":{"html":"https://cve.report/CVE-2020-5555","api":"https://cve.report/api/cve/CVE-2020-5555.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-5555","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-5555"},"summary":{"title":"CVE-2020-5555","description":"Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is placed via unspecified vector due to the improper input validation issue.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2020-03-25 02:15:00","updated_at":"2020-03-26 18:38:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://jvn.jp/en/jp/JVN32415420/index.html","name":"https://jvn.jp/en/jp/JVN32415420/index.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"JVN#32415420: Multiple vulnerabiliteis in Shihonkanri Plus GOOUT","mime":"text/xml","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-5555","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5555","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"5555","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"shihonkanri_plus_goout_project","cpe5":"shihonkanri_plus_goout","cpe6":"1.5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5555","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"shihonkanri_plus_goout_project","cpe5":"shihonkanri_plus_goout","cpe6":"2.2.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5555","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"shihonkanri_plus_goout_project","cpe5":"shihonkanri_plus_goout","cpe6":"1.5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5555","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"shihonkanri_plus_goout_project","cpe5":"shihonkanri_plus_goout","cpe6":"2.2.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","references":{"reference_data":[{"url":"https://jvn.jp/en/jp/JVN32415420/index.html","refsource":"MISC","name":"https://jvn.jp/en/jp/JVN32415420/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is placed via unspecified vector due to the improper input validation issue."}]},"data_type":"CVE","affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"version":{"version_data":[{"version_value":"Ver1.5.8 and Ver2.2.10"}]},"product_name":"Shihonkanri Plus GOOUT"}]},"vendor_name":"EKAKIN"}]}},"CVE_data_meta":{"ID":"CVE-2020-5555","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"data_format":"MITRE","problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Input Validation"}]}]}},"nvd":{"publishedDate":"2020-03-25 02:15:00","lastModifiedDate":"2020-03-26 18:38:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:shihonkanri_plus_goout_project:shihonkanri_plus_goout:2.2.10:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:shihonkanri_plus_goout_project:shihonkanri_plus_goout:1.5.8:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"5555","Ordinal":"165801","Title":"CVE-2020-5555","CVE":"CVE-2020-5555","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"5555","Ordinal":"1","NoteData":"Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is placed via unspecified vector due to the improper input validation issue.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"5555","Ordinal":"2","NoteData":"2020-03-24","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"5555","Ordinal":"3","NoteData":"2020-03-24","Type":"Other","Title":"Modified"}]}}}