CVE-2020-6932
CRITICALBlackBerry QNX SDP 6.4.0-6.6.0 - Info Disclosure & RCE in Slinger Web Server
Title source: llmDescription
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
http://support.blackberry.com/kb/articleDetail?articleNumber=000061411
Scores
CVSS v3
10.0
EPSS
0.0359
EPSS Percentile
88.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Details
CWE
CWE-150
Status
published
Products (1)
blackberry/qnx_software_development_platform
6.4.0 - 6.6.0
Published
Aug 12, 2020
Tracked Since
Feb 18, 2026