CVE Feed

    Dashboard / CVE / CVE-2020-15492

    CVE-2020-15492

    An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.

    Published:Jul 23, 2020
    Last Modified:Nov 21, 2024
    EPS:Jul 23, 2020
    EPSS Score:0.37735
    CVSS Score:9.8

    Affected Products

    Vendor
    Inneo
    Product
    Startup Tools

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High