🔙 목록으로 돌아가기

CVE-2020-9047: exacqVision Web Service - Remote Code Execution

TitleexacqVision Web Service - Remote Code Execution
Authordwisiswant0
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patch or update provided by the vendor to fix the vulnerability.
CVSS Score7.2
EPSS Score0.17828
CVE IDCVE-2020-9047
CWE IDCWE-347
Tags cve cve2020 rce exacqvision johnsoncontrols vuln

🔍 Vulnerability Description

exacqVision Web Service is susceptible to remote code execution which could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentiallydownload and run a malicious executable that could allow OS command injection on the system.

🌐 HTTP Request

GET /version.web HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-9047.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-9047.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A