CVE-2020-6932

CRITICAL

BlackBerry QNX SDP 6.4.0-6.6.0 - Info Disclosure & RCE in Slinger Web Server

Title source: llm
STIX 2.1

Description

An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.

References (1)

Core 1
Core References

Scores

CVSS v3 10.0
EPSS 0.0359
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-150
Status published
Products (1)
blackberry/qnx_software_development_platform 6.4.0 - 6.6.0
Published Aug 12, 2020
Tracked Since Feb 18, 2026