EXPOSURES › CVE-2020-26867
CVE-2020-26867
CRITICAL
DETAIL
SourceNVD · cve
Published2020-10-12
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-26867 ↗
⚡ RCE
SHAME 50/100
rce
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.50
Vulnerability disclosed via NVD, no vendor response or praise found in sources.
Damning disclosure
"vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code"
Neutral listing
Neutral listing
Neutral listing
Neutral listing
Neutral listing
Neutral listing
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.