CVE Published: 03/02/2020 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: twcert |
Vendor: CHANGING |
Product: ServiSign Windows versions Status : PUBLISHED
CVE-2020-3926 Description
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Metrics
CVSS Version: 3.1 |
Base Score: 6.1 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N