CVE-2020-29551
CRITICAL
9,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: high
HIGH
8,5
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: none
Availability: complete
Description
AI Translation Available
An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php, _internal/pc/vpro.php, _internal/pc/wake.php, _internal/error_u201409.txt, _internal/runcmd.php, _internal/getConfiguration.php, ews/autoload.php, ews/del.php, ews/mod.php, ews/sync.php, utils/backup/backup_server.php, utils/backup/restore_server.php, MyScreens/timeline.config, kreator.html5/test.php, and addedlogs.txt.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0341
Percentile
0,9th
Updated
EPSS Score Trend (Last 91 Days)
306
Missing Authentication for Critical Function
DraftCommon Consequences
Security Scopes Affected:
Access Control
Other
Potential Impacts:
Gain Privileges Or Assume Identity
Varies By Context
Applicable Platforms
Technologies:
Cloud Computing, ICS/OT
Application
Urve by Urve
CPE Identifier
View Detailed Analysis
cpe:2.3:a:urve:urve:24.03.2020:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://packetstormsecurity.com/files/160725/URVE-Software-Build-24.03.2020-Miss…
http://seclists.org/fulldisclosure/2020/Dec/48
https://urve.co.uk/system-rezerwacji-sal
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-041.…
http://packetstormsecurity.com/files/160725/URVE-Software-Build-24.03.2020-Miss…
http://seclists.org/fulldisclosure/2020/Dec/48
https://urve.co.uk/system-rezerwacji-sal
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-041.…