CVE-2020-5685: OS Command Injection
UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5685.
What is the title of this vulnerability?
The title of this vulnerability is 'UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL.'
What is the severity of CVE-2020-5685?
The severity of CVE-2020-5685 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2020-5685?
The UNIVERGE SV9500 series from V1 to V7 and SV8500 series from S6 to S8 are affected by CVE-2020-5685.
How can an attacker exploit this vulnerability?
An attacker can exploit CVE-2020-5685 by sending a specially crafted request to a specific URL, which allows them to execute arbitrary OS commands or cause a denial-of-service (DoS) condition.