Exposure of Resource to Wrong Sphere in ExactaMix EM1200 and ExactaMix EM2400 - CVE-2020-12020

 

Exposure of Resource to Wrong Sphere in ExactaMix EM1200 and ExactaMix EM2400 - CVE-2020-12020

Published: June 19, 2020


Vulnerability identifier: #VU29173
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12020
CWE-ID:
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to the affected software does not restrict non administrative users from gaining access to the operating system and editing the application startup script. A local user can alter the startup script as the limited-access user.


Affected software

ExactaMix EM1200
ExactaMix EM2400

How to mitigate CVE-2020-12020

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins