7.2
CVSSv3

CVE-2020-9047

Published: 26/06/2020 Updated: 26/05/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols exacqvision enterprise manager

johnsoncontrols exacqvision web service

Github Repositories

Usage/Help Menu usage: CVE-2020-9047py [-h] [-p RPORT] [-s LPORT] [--command] [-d WEBDIR] [-U USERNAME] [-P PASSWORD] {WINDOWS,LINUX,CHECK} RHOST LHOST PAYLOAD Exploit for exacqVision Web Service as outlined in CVE-2020-9047 This program targets Windows and Linux x86 installations of exacqVision Web Service versions 38267295