Skip to content
COOEY

EXPOSURES › CVE-2020-1956

CVE-2020-1956

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-1956 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Apache Kylin OS had an unpatched command injection flaw allowing remote code execution.

An OS command injection vulnerability in Apache Kylin allowed attackers to execute arbitrary commands remotely, leading to potential system compromise. DIB organizations must ensure all software, especially operating systems, are patched against known CVEs to prevent similar exploits. This failure highlights the risk of relying on unpatched software in critical infrastructure.

Shame score — The vulnerability was actively exploited in the wild (KEV list) and allowed remote code execution, indicating a severe and avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.