CVE-2020-13536
Severity
7.8HIGH
EPSS
0.0%
top 91.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 5
Latest updateMay 24
Description
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-f9j2-hv33-h2gp: An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3↗2022-05-24
CVEList▶
CVE-2020-13536: An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3↗2020-11-05