7.5
CVSSv2

CVE-2020-15492

Published: 23/07/2020 Updated: 28/07/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated malicious user to read files on the server via Directory Traversal, or possibly have unspecified other impact.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

inneo startup tools

Exploits

INNEO Startup TOOLS 2018 M040 version 130703804 remote code execution exploit ...

Github Repositories

This repository holds the advisory, exploits and vulnerable software of the CVE-2020-15492

CVE-2020-15492 This vulnerablity was discovered and disclosed by me This repository will hold the advisory, exploits and the setup executable of the vulnerable software for one to experiment with this vulnerability This repository is only for educational purposes Links Advisory SYSS-2020-028 SySS Blog entry Exploit on Exploit-DB Vendor notice MITRE Entry NVD Entry