CVE-2020-5569
An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS, HD-MA10TS), CANVIO SLIM 1TB(HD-SB10TK, HD-SB10TS), and CANVIO SLIM 500GB(HD-SB50GK, HD-SA50GK, HD-SB50GS, HD-SA50GS), and which was downloaded before 2020 May 10. Since it registers Windows services with unquoted file paths, when a registered path contains spaces, and a malicious executable is placed on a certain path, it may be executed with the privilege of the Windows service.
Published:Apr 20, 2020
Last Modified:Nov 21, 2024
EPS:Apr 20, 2020
EPSS Score:0.00162
CVSS Score:8.4
Affected Products
Vendor
Product
Action
Vendor
Toshiba
Product
Hd-ma10ts
Toshiba
Hd-ma10ts
Vendor
Toshiba
Product
Hd-ma10ty
Toshiba
Hd-ma10ty
Vendor
Toshiba
Product
Hd-ma20ts
Toshiba
Hd-ma20ts
Vendor
Toshiba
Product
Hd-ma20ty
Toshiba
Hd-ma20ty
Vendor
Toshiba
Product
Hd-ma30ts
Toshiba
Hd-ma30ts
Vendor
Toshiba
Product
Hd-ma30ty
Toshiba
Hd-ma30ty
Vendor
Toshiba
Product
Hd-mb10ts
Toshiba
Hd-mb10ts
Vendor
Toshiba
Product
Hd-mb10ty
Toshiba
Hd-mb10ty
Vendor
Toshiba
Product
Hd-mb20ts
Toshiba
Hd-mb20ts
Vendor
Toshiba
Product
Hd-mb20ty
Toshiba
Hd-mb20ty
Vendor
Toshiba
Product
Hd-mb30ts
Toshiba
Hd-mb30ts
Vendor
Toshiba
Product
Hd-mb30ty
Toshiba
Hd-mb30ty
Vendor
Toshiba
Product
Hd-sa50gk
Toshiba
Hd-sa50gk
Vendor
Toshiba
Product
Hd-sa50gs
Toshiba
Hd-sa50gs
Vendor
Toshiba
Product
Hd-sb10tk
Toshiba
Hd-sb10tk
Vendor
Toshiba
Product
Hd-sb10ts
Toshiba
Hd-sb10ts
Vendor
Toshiba
Product
Hd-sb50gk
Toshiba
Hd-sb50gk
Vendor
Toshiba
Product
Hd-sb50gs
Toshiba
Hd-sb50gs
Vendor
Toshiba
Product
Password Tool For Windows
Toshiba
Password Tool For Windows
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
