CVE-2020-13938
published 2021-06-10CVE-2020-13938: Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
PriorityP430medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
11.77%
95.6th percentile
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.4.0 – 2.4.46 | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qvx2-v283-5hp3: Apache HTTP Server versions 2
ghsa_unreviewed·2022-05-24
CVE-2020-13938 [MEDIUM] CWE-862 GHSA-qvx2-v283-5hp3: Apache HTTP Server versions 2
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
OSV
CVE-2020-13938: Apache HTTP Server versions 2
osv·2021-06-10·CVSS 5.5
CVE-2020-13938 [MEDIUM] CVE-2020-13938: Apache HTTP Server versions 2
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
CISA ICS
Mitsubishi Electric MELSOFT iQ AppPortal
cisa_ics·2022-05-12·CVSS 5.5
[MEDIUM] Mitsubishi Electric MELSOFT iQ AppPortal
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric MELSOFT iQ AppPortal
Last RevisedMay 12, 2022
Alert CodeICSA-22-132-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Mitsubishi Electric
- Equipment: MELSOFT iQ AppPortal
- Vulnerabilities: Missing Authorization, Out-of-bounds Write, NULL Pointer Dereference, Classic Buffer Overflow, HTTP Request Smuggling, Infinite Loop
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a denial-of-service condition, malicious program execution, information disclosure, informa
Red Hat
httpd: Improper Handling of Insufficient Privileges
vendor_redhat·2021-06-07·CVSS 5.5
CVE-2020-13938 [MEDIUM] CWE-732 httpd: Improper Handling of Insufficient Privileges
httpd: Improper Handling of Insufficient Privileges
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
A flaw was found in HTTPd. In some Apache HTTP Server versions, unprivileged local users can stop HTTPd on Windows. The highest threat from this vulnerability is to system availability.
Statement: As per upstream, this flaw affects only Microsoft Windows operating system, therefore Red Hat Enterprise Linux and Red Hat Software Collection is not affected by this flaw.
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: httpd:2.4/httpd (Red Hat Enterprise Linux 8) - Not affected
Package: httpd (Red Hat Enterprise Linux 9) - Not affected
Package: httpd (Red Hat JBoss
Debian
CVE-2020-13938: apache2 - Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop ht...
vendor_debian·2020·CVSS 5.5
CVE-2020-13938 [MEDIUM] CVE-2020-13938: apache2 - Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop ht...
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/3https://kc.mcafee.com/corporate/index?page=content&id=SB10379https://lists.apache.org/thread.html/r5fdc4fbbc7ddb816c843329a9accdcf284ade86e8d77b8c2a6d9bc30%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210702-0001/http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/3https://kc.mcafee.com/corporate/index?page=content&id=SB10379https://lists.apache.org/thread.html/r5fdc4fbbc7ddb816c843329a9accdcf284ade86e8d77b8c2a6d9bc30%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210702-0001/
2021-06-10
Published