CVE-2020-9048
08.10.2020, 18:15
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack.Enginsight
Vendor | Product | Version |
---|---|---|
johnsoncontrols | victor_web_client | 𝑥 ≤ 5.4.1 |
tyco | c-cure_web_client | 𝑥 ≤ 2.80 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-285 - Improper AuthorizationThe software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.