CVE-2020-36903
Last modified
CVE-2020-36903 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that allows local users to potentially execute code with elevated privileges. Attackers can exploit the service's unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during application startup or reboot.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that allows local users to potentially execute code with elevated privileges. Attackers can exploit the service's unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during application startup or reboot.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2020-36903?
How severe is CVE-2020-36903?
How do I fix CVE-2020-36903?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-36898QiHang Media Web Digital Signage 3.0.9 contains an unauthent…9.1
- CVE-2020-36899QiHang Media Web Digital Signage 3.0.9 contains an unauthent…7.5
- CVE-2020-3690u'Due to an incorrect SMMU configuration, the modem crypto e…7.8
- CVE-2020-36900All-Dynamics Digital Signage System 2.0.2 contains a cross-s…8.8
- CVE-2020-36901UBICOD Medivision Digital Signage 1.5.1 contains a cross-sit…8.8
- CVE-2020-36902UBICOD Medivision Digital Signage 1.5.1 contains an authoriz…9.8
- CVE-2020-36904Selea CarPlateServer 4.0.1.6 contains a remote program execu…9.3
- CVE-2020-36905FIBARO System Home Center 5.021 contains a remote file inclu…7.5
- CVE-2020-36906P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request…5.3
- CVE-2020-36907Aerohive HiveOS contains a denial of service vulnerability i…8.7
- CVE-2020-36908SnapGear Management Console SG560 version 3.1.5 contains a c…8.8
- CVE-2020-36909SnapGear Management Console SG560 3.1.5 contains a file mani…8.8
Are you affected by CVE-2020-36903?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
