CVE-2020-10603: OS Command Injection
Published Apr 9, 2020
·Updated
WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.
Affected Software
1 affected component
Advantech Webaccess\/nms<3.0.2
Event History
Apr 9, 2020
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-10603?
CVE-2020-10603 is categorized as a high-severity vulnerability due to the potential for remote command injection.
2
How do I fix CVE-2020-10603?
To mitigate CVE-2020-10603, upgrade WebAccess/NMS to version 3.0.2 or later to ensure proper input sanitization.
3
What versions of WebAccess/NMS are affected by CVE-2020-10603?
CVE-2020-10603 affects all versions of WebAccess/NMS prior to 3.0.2.
4
What type of attacks can be executed through CVE-2020-10603?
CVE-2020-10603 may allow attackers to inject system commands remotely, potentially compromising the system.
5
Can CVE-2020-10603 be exploited remotely?
Yes, CVE-2020-10603 can be exploited remotely due to improper input sanitization in the affected software.