Skip to content
COOEY

EXPOSURES › CVE-2020-26867

CVE-2020-26867

CRITICAL
DETAIL
SourceNVD · cve Published2020-10-12 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-26867 ↗
⚡ RCE SHAME 50/100 rce

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.50
Vulnerability disclosed via NVD, no vendor response or praise found in sources.
cooey ↗ severe-fallout -0.80
Damning disclosure
"vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code"
www.cvefind.com ↗ severe-fallout +0.00
Neutral listing
chromereleases.googleblog.com ↗ severe-fallout +0.00
Neutral listing
advisories.gitlab.com ↗ severe-fallout +0.00
Neutral listing
CISA ↗ severe-fallout +0.00
Neutral listing
classactionu.org ↗ severe-fallout +0.00
Neutral listing
www.rescana.com ↗ severe-fallout +0.00
Neutral listing
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.