CVE-2020-9047
MEDIUM NUCLEIJohnsoncontrols Exacqvision Enterpris... - Signature Verification Bypass
Title source: ruleDescription
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.
Exploits (1)
Nuclei Templates (1)
exacqVision Web Service - Remote Code Execution
HIGHby dwisiswant0
Scores
CVSS v3
6.8
EPSS
0.1783
EPSS Percentile
95.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L
Details
CWE
CWE-347
Status
published
Products (2)
johnsoncontrols/exacqvision_enterprise_manager
< 20.06.4.0
johnsoncontrols/exacqvision_web_service
< 20.06.3.0
Published
Jun 26, 2020
Tracked Since
Feb 18, 2026