CVE-2020-10583

HIGH

Invigo ADM <5.0 - Command Injection

Title source: llm
STIX 2.1

Description

The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0277
EPSS Percentile 84.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
invigo/automatic_device_management < 5.0
Published Mar 25, 2021
Tracked Since Feb 18, 2026