CVE-2020-12525

EUVD-2020-4827
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CERTVDECNA
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
Affected Products (NVD)
VendorProductVersion
emersonrosemount_transmitter_interface_software
-
pepperl-fuchspactware
5.0 ≤
𝑥
≤ 5.0.5.31
wagodtminspector_3
-
wagofdtcontainer_application
𝑥
< 4.5
wagofdtcontainer_application
4.5.0 ≤
𝑥
≤ 4.5.20304
wagofdtcontainer_application
4.6.0 ≤
𝑥
≤ 4.6.20304
wagofdtcontainer_component
𝑥
< 3.5
wagofdtcontainer_component
3.5.0 ≤
𝑥
≤ 3.5.20304
wagofdtcontainer_component
3.6.0 ≤
𝑥
≤ 3.6.20304
weidmuellerwi_manager
𝑥
≤ 2.5.1
pepperl-fuchsio-link_master_firmware
𝑥
≤ 1.5.48
𝑥
= Vulnerable software versions