← Retour aux CVEs
CVE-2020-8810
HIGH8.1
Description
An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable files and place them in an autorun directory, or to place DLLs inside the existing GXDLMS Director installation (run on next execution of GXDLMS Director). This can be used to achieve code execution even if the user doesn't have any add-ins installed.
Details CVE
Score CVSS v3.18.1
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie2/25/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
gurux:device_language_message_specification_director
Faiblesses (CWE)
CWE-22
References
https://github.com/seqred-s-a/gxdlmsdirector-cve(cve@mitre.org)
https://seqred.pl/en/cve-gurux-gxdlms-director/(cve@mitre.org)
https://github.com/seqred-s-a/gxdlmsdirector-cve(af854a3a-2127-422b-91ae-364da2661108)
https://seqred.pl/en/cve-gurux-gxdlms-director/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.