CVE-2020-16245
CVE-2020-16245
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 7.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
25 Aug 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
Affected products
n/a · Advantech iViewWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://us-cert.cisa.gov/ics/advisories/icsa-20-238-01https://www.zerodayinitiative.com/advisories/ZDI-20-1084/https://www.zerodayinitiative.com/advisories/ZDI-20-1085/https://www.zerodayinitiative.com/advisories/ZDI-20-1086/https://www.zerodayinitiative.com/advisories/ZDI-20-1087/https://www.zerodayinitiative.com/advisories/ZDI-20-1088/https://www.zerodayinitiative.com/advisories/ZDI-20-1089/https://www.zerodayinitiative.com/advisories/ZDI-20-1090/https://www.zerodayinitiative.com/advisories/ZDI-20-1091/https://www.zerodayinitiative.com/advisories/ZDI-20-1092/