← back
CVE-2020-26992

CVE-2020-26992

EPSS 1.6%CWE-121
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Jan 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →