EXPOSURES › CVE-2020-25466
CVE-2020-25466
CRITICAL
DETAIL
SourceNVD · cve
Published2020-10-23
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25466 ↗
⚡ RCE
SHAME 50/100
rce
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CRMEB's vulnerability was confirmed exploited and added to CISA KEV, indicating critical risk and regulatory scrutiny.
Confirmed critical SSRF flaw enabling remote code execution
"A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code."
Mirrors CISA KEV, highlighting active exploitation
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management."
Cataloged as a known vulnerability for tracking
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
Irrelevant to CRMEB vulnerability
Irrelevant to CRMEB vulnerability
Irrelevant to CRMEB vulnerability
Irrelevant to CRMEB vulnerability
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.