PoC Index

CVE-2020-15492

CRITICAL 9.8EPSS 16.6%

An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
16.59% chance of exploitation in the next 30 days, 97th percentile
Published
2020-07-23
Updated
2024-08-04

Proof-of-concept exploits (3)

ExploitDB entries (1)

References

Related