CVE-2020-25842

HIGH

Panorama Nhiservisignadapter - Missing Encryption

Title source: rule
STIX 2.1

Description

The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.

Scores

CVSS v3 7.5
EPSS 0.0008
EPSS Percentile 24.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-311
Status published
Products (1)
panorama/nhiservisignadapter 1.0.20.0218
Published Dec 31, 2020
Tracked Since Feb 18, 2026