Description
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.
Published: 2020-06-26
Score: 6.8 Medium
EPSS: 17.8% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade all versions of exacqVision Web Service to version 20.06.2.0 or higher Upgrade all versions of exacqVision Enterprise Manager to version 20.06.3.0 or higher Current users can obtain the critical software update from the Software Downloads location at https://www.exacq.com/support/downloads.php

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Johnsoncontrols Exacqvision Enterprise Manager Exacqvision Web Service
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2024-08-04T10:19:19.396Z

Reserved: 2020-02-18T00:00:00.000Z

Link: CVE-2020-9047

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-26T19:15:10.453

Modified: 2024-11-21T05:39:53.777

Link: CVE-2020-9047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses